Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 665081 Details for
Bug 887927
Examine and fix if necessary Coverity issues in TCG code
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
Coverity scan results
qemu-1.2.0-25.fc19.html (text/html), 3.24 MB, created by
Richard W.M. Jones
on 2012-12-17 19:55:37 UTC
(
hide
)
Description:
Coverity scan results
Filename:
MIME Type:
Creator:
Richard W.M. Jones
Created:
2012-12-17 19:55:37 UTC
Size:
3.24 MB
patch
obsolete
><?xml version='1.0' encoding='utf-8'?> ><!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.1//EN' 'http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd'> ><html xmlns='http://www.w3.org/1999/xhtml'> ><head><title>qemu-1.2.0-25.fc19</title></head> ><body> ><h1>qemu-1.2.0-25.fc19</h1> ><a href='qemu-1.2.0-25.fc19.err'>[Show plain-text results]</a> ><h2>List of Defects</h2> ><pre style='white-space: pre-wrap;'> ><a name='def1'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def1'>[#def1]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1858: <b>cond_true</b>: Condition "nb_regs > nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1865: <b>cond_false</b>: Condition "call_stack_size > 128", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1866: <b>cond_false</b>: Condition "allocate_args", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1870: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>cond_false</b>: Condition "ts->val_type == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>cond_true</b>: Condition "ts->val_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1894: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_false</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1897: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_false</b>: Condition "i < nb_params", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1912: <b>cond_true</b>: Condition "ts->reg != reg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1912: <b>cond_true</b>: Condition "ts->reg != reg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1917: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_false</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1924: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_false</b>: Condition "i < nb_regs", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1933: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1938: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1958: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_true</b>: Condition "i < nb_iargs + nb_oargs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1964: <b>cond_true</b>: Condition "(dead_args >> i) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1966: <b>cond_true</b>: Condition "!ts->fixed_reg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1967: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_true</b>: Condition "i < nb_iargs + nb_oargs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1964: <b>cond_true</b>: Condition "(dead_args >> i) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1966: <b>cond_false</b>: Condition "!ts->fixed_reg", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1970: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_false</b>: Condition "i < nb_iargs + nb_oargs", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_true</b>: Condition "reg < 16", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1976: <b>cond_true</b>: Condition "(tcg_target_call_clobber_regs >> reg) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_true</b>: Condition "reg < 16", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1976: <b>cond_true</b>: Condition "(tcg_target_call_clobber_regs >> reg) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_false</b>: Condition "reg < 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1983: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1987: <b>address_of</b>: Taking address with "&func_arg" yields a singleton pointer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1987: <b>callee_ptr_arith</b>: Passing "&func_arg" to function "tcg_out_op(TCGContext *, TCGOpcode, TCGArg const *, int const *)" which uses it as an array. This might corrupt or misinterpret adjacent memory locations.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1504:5: <b>switch</b>: Switch case value "INDEX_op_movi_i32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1541:10: <b>switch_case</b>: Reached case "INDEX_op_movi_i32"</span> >qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1542:9: <b>ptr_arith</b>: Performing pointer arithmetic on "args" in expression "args + 1". > ><a name='def2'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def2'>[#def2]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:657: <b>address_of</b>: Taking address with "&d->ram->release_ring" yields a singleton pointer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:657: <b>assign</b>: Assigning: "ring" = "&d->ram->release_ring".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:663: <b>cond_false</b>: Condition "ring->prod - ring->cons + 1 == ring->num_items", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:667: <b>cond_true</b>: Condition "!flush", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:667: <b>cond_false</b>: Condition "d->oom_running", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:670: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:671: <b>cond_true</b>: Condition "!flush", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:671: <b>cond_false</b>: Condition "d->num_free_res < 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:674: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:676: <b>cond_true</b>: Condition "ring->prod == ring->notify_on_prod", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:677: <b>cond_true</b>: Condition "notify", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:682: <b>cond_true</b>: Condition "notify", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:685: <b>assign</b>: Assigning: "start" = "ring".</span> >qemu-kvm-1.2.0/hw/qxl.c:685: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. > ><a name='def3'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def3'>[#def3]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:588: <b>switch</b>: Switch case value "QXL_MODE_COMPAT"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:604: <b>switch_case</b>: Reached case "QXL_MODE_COMPAT"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:607: <b>address_of</b>: Taking address with "&qxl->ram->cmd_ring" yields a singleton pointer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:607: <b>assign</b>: Assigning: "ring" = "&qxl->ram->cmd_ring".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:608: <b>cond_false</b>: Condition "qxl->guest_bug", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:608: <b>cond_false</b>: Condition "ring->cons == ring->prod", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:610: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:611: <b>assign</b>: Assigning: "start" = "ring".</span> >qemu-kvm-1.2.0/hw/qxl.c:611: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. > ><a name='def4'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def4'>[#def4]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:748: <b>switch</b>: Switch case value "QXL_MODE_COMPAT"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:749: <b>switch_case</b>: Reached case "QXL_MODE_COMPAT"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:752: <b>address_of</b>: Taking address with "&qxl->ram->cursor_ring" yields a singleton pointer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:752: <b>assign</b>: Assigning: "ring" = "&qxl->ram->cursor_ring".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:753: <b>cond_false</b>: Condition "ring->cons == ring->prod", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:755: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:756: <b>assign</b>: Assigning: "start" = "ring".</span> >qemu-kvm-1.2.0/hw/qxl.c:756: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. > ><a name='def5'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def5'>[#def5]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:703: <b>cond_false</b>: Condition "ext.group_id == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:713: <b>address_of</b>: Taking address with "&qxl->ram->release_ring" yields a singleton pointer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:713: <b>assign</b>: Assigning: "ring" = "&qxl->ram->release_ring".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:714: <b>assign</b>: Assigning: "start" = "ring".</span> >qemu-kvm-1.2.0/hw/qxl.c:714: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. > ><a name='def6'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def6'>[#def6]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:392: <b>address_of</b>: Taking address with "&d->ram->release_ring" yields a singleton pointer.</span> >qemu-kvm-1.2.0/hw/qxl.c:392: <b>ptr_arith</b>: Using "&d->ram->release_ring" as an array. This might corrupt or misinterpret adjacent memory locations. > ><a name='def7'/><b>Error: <span style='background: #C0FF00;'>ATOMICITY</span> (CWE-662):</b> <a href ='#def7'>[#def7]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:296: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:298: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:300: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:303: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:304: <b>cond_false</b>: Condition "pa->done", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:306: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:308: <b>cond_true</b>: Condition "pa->dead > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:309: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:315: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:317: <b>cond_true</b>: Condition "ta > tb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:296: <b>lock</b>: Locking "pa->pt.mutex".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:318: <b>def</b>: Assigning data that might be protected by the lock to "wpos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:320: <b>unlock</b>: Unlocking "pa->pt.mutex". "wpos" might now be unreliable because other threads can now change the data that it depends on.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:320: <b>cond_false</b>: Condition "audio_pt_unlock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:322: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:324: <b>cond_false</b>: Condition "to_grab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:338: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:340: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:342: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:340: <b>lockagain</b>: Locking "pa->pt.mutex" again.</span> >qemu-kvm-1.2.0/audio/paaudio.c:344: <b>use</b>: Using an unreliable value of "wpos" inside the second locked section. If the data that "wpos" depends on was changed by another thread, this use might be incorrect. > ><a name='def8'/><b>Error: <span style='background: #C0FF00;'>ATOMICITY</span> (CWE-662):</b> <a href ='#def8'>[#def8]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:204: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:208: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:211: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:212: <b>cond_false</b>: Condition "pa->done", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:214: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:216: <b>cond_true</b>: Condition "pa->live > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:217: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:223: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:225: <b>cond_true</b>: Condition "ta > tb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:204: <b>lock</b>: Locking "pa->pt.mutex".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:226: <b>def</b>: Assigning data that might be protected by the lock to "rpos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:228: <b>unlock</b>: Unlocking "pa->pt.mutex". "rpos" might now be unreliable because other threads can now change the data that it depends on.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:228: <b>cond_false</b>: Condition "audio_pt_unlock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:230: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:232: <b>cond_false</b>: Condition "to_mix", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:247: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:249: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:251: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:249: <b>lockagain</b>: Locking "pa->pt.mutex" again.</span> >qemu-kvm-1.2.0/audio/paaudio.c:253: <b>use</b>: Using an unreliable value of "rpos" inside the second locked section. If the data that "rpos" depends on was changed by another thread, this use might be incorrect. > ><a name='def9'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def9'>[#def9]</a> >qemu-kvm-1.2.0/trace.h:1116: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def10'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def10'>[#def10]</a> >qemu-kvm-1.2.0/trace.h:1116: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def11'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def11'>[#def11]</a> >qemu-kvm-1.2.0/trace.h:1128: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def12'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def12'>[#def12]</a> >qemu-kvm-1.2.0/trace.h:1128: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def13'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def13'>[#def13]</a> >qemu-kvm-1.2.0/trace.h:1119: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def14'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def14'>[#def14]</a> >qemu-kvm-1.2.0/trace.h:1119: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def15'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def15'>[#def15]</a> >qemu-kvm-1.2.0/trace.h:21: <b>bad_sizeof</b>: Taking the size of pointer parameter "newptr" is suspicious. > ><a name='def16'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def16'>[#def16]</a> >qemu-kvm-1.2.0/trace.h:21: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def17'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def17'>[#def17]</a> >qemu-kvm-1.2.0/trace.h:2169: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_state" is suspicious. > ><a name='def18'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def18'>[#def18]</a> >qemu-kvm-1.2.0/trace.h:2169: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. > ><a name='def19'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def19'>[#def19]</a> >qemu-kvm-1.2.0/trace.h:903: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def20'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def20'>[#def20]</a> >qemu-kvm-1.2.0/trace.h:915: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. > ><a name='def21'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def21'>[#def21]</a> >qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def22'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def22'>[#def22]</a> >qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "filename" is suspicious. > ><a name='def23'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def23'>[#def23]</a> >qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "format_name" is suspicious. > ><a name='def24'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def24'>[#def24]</a> >qemu-kvm-1.2.0/trace.h:90: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def25'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def25'>[#def25]</a> >qemu-kvm-1.2.0/trace.h:90: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def26'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def26'>[#def26]</a> >qemu-kvm-1.2.0/trace.h:489: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def27'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def27'>[#def27]</a> >qemu-kvm-1.2.0/trace.h:486: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def28'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def28'>[#def28]</a> >qemu-kvm-1.2.0/trace.h:492: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def29'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def29'>[#def29]</a> >qemu-kvm-1.2.0/trace.h:495: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def30'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def30'>[#def30]</a> >qemu-kvm-1.2.0/trace.h:2172: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_state" is suspicious. > ><a name='def31'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def31'>[#def31]</a> >qemu-kvm-1.2.0/trace.h:2172: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. > ><a name='def32'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def32'>[#def32]</a> >qemu-kvm-1.2.0/trace.h:144: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. > ><a name='def33'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def33'>[#def33]</a> >qemu-kvm-1.2.0/trace.h:141: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. > ><a name='def34'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def34'>[#def34]</a> >qemu-kvm-1.2.0/trace.h:135: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. > ><a name='def35'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def35'>[#def35]</a> >qemu-kvm-1.2.0/trace.h:138: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. > ><a name='def36'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def36'>[#def36]</a> >qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "n" is suspicious. > ><a name='def37'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def37'>[#def37]</a> >qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "o" is suspicious. > ><a name='def38'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def38'>[#def38]</a> >qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def39'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def39'>[#def39]</a> >qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def40'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def40'>[#def40]</a> >qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "n" is suspicious. > ><a name='def41'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def41'>[#def41]</a> >qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "o" is suspicious. > ><a name='def42'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def42'>[#def42]</a> >qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def43'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def43'>[#def43]</a> >qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. > ><a name='def44'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def44'>[#def44]</a> >qemu-kvm-1.2.0/trace.h:117: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def45'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def45'>[#def45]</a> >qemu-kvm-1.2.0/trace.h:2160: <b>bad_sizeof</b>: Taking the size of pointer parameter "cb" is suspicious. > ><a name='def46'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def46'>[#def46]</a> >qemu-kvm-1.2.0/trace.h:2160: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. > ><a name='def47'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def47'>[#def47]</a> >qemu-kvm-1.2.0/trace.h:2157: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. > ><a name='def48'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def48'>[#def48]</a> >qemu-kvm-1.2.0/trace.h:2163: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. > ><a name='def49'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def49'>[#def49]</a> >qemu-kvm-1.2.0/trace.h:2166: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. > ><a name='def50'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def50'>[#def50]</a> >qemu-kvm-1.2.0/trace.h:2154: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def51'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def51'>[#def51]</a> >qemu-kvm-1.2.0/trace.h:2154: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. > ><a name='def52'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def52'>[#def52]</a> >qemu-kvm-1.2.0/trace.h:51: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. > ><a name='def53'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def53'>[#def53]</a> >qemu-kvm-1.2.0/trace.h:51: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def54'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def54'>[#def54]</a> >qemu-kvm-1.2.0/trace.h:36: <b>bad_sizeof</b>: Taking the size of pointer parameter "elem" is suspicious. > ><a name='def55'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def55'>[#def55]</a> >qemu-kvm-1.2.0/trace.h:36: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def56'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def56'>[#def56]</a> >qemu-kvm-1.2.0/trace.h:39: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def57'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def57'>[#def57]</a> >qemu-kvm-1.2.0/trace.h:45: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. > ><a name='def58'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def58'>[#def58]</a> >qemu-kvm-1.2.0/trace.h:45: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def59'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def59'>[#def59]</a> >qemu-kvm-1.2.0/trace.h:1548: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. > ><a name='def60'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def60'>[#def60]</a> >qemu-kvm-1.2.0/trace.h:1545: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. > ><a name='def61'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def61'>[#def61]</a> >qemu-kvm-1.2.0/trace.h:1551: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. > ><a name='def62'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def62'>[#def62]</a> >qemu-kvm-1.2.0/trace.h:42: <b>bad_sizeof</b>: Taking the size of pointer parameter "elem" is suspicious. > ><a name='def63'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def63'>[#def63]</a> >qemu-kvm-1.2.0/trace.h:42: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def64'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def64'>[#def64]</a> >qemu-kvm-1.2.0/trace.h:54: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. > ><a name='def65'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def65'>[#def65]</a> >qemu-kvm-1.2.0/trace.h:822: <b>bad_sizeof</b>: Taking the size of pointer parameter "f" is suspicious. > ><a name='def66'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def66'>[#def66]</a> >qemu-kvm-1.2.0/trace.h:819: <b>bad_sizeof</b>: Taking the size of pointer parameter "f" is suspicious. > ><a name='def67'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def67'>[#def67]</a> >qemu-kvm-1.2.0/trace.h:1908: <b>bad_sizeof</b>: Taking the size of pointer parameter "cmd_name" is suspicious. > ><a name='def68'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def68'>[#def68]</a> >qemu-kvm-1.2.0/trace.h:1908: <b>bad_sizeof</b>: Taking the size of pointer parameter "mon" is suspicious. > ><a name='def69'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def69'>[#def69]</a> >qemu-kvm-1.2.0/trace.h:1029: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def70'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def70'>[#def70]</a> >qemu-kvm-1.2.0/trace.h:1026: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def71'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def71'>[#def71]</a> >qemu-kvm-1.2.0/trace.h:1020: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def72'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def72'>[#def72]</a> >qemu-kvm-1.2.0/trace.h:1023: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def73'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def73'>[#def73]</a> >qemu-kvm-1.2.0/trace.h:1017: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def74'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def74'>[#def74]</a> >qemu-kvm-1.2.0/trace.h:102: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def75'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def75'>[#def75]</a> >qemu-kvm-1.2.0/trace.h:108: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def76'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def76'>[#def76]</a> >qemu-kvm-1.2.0/trace.h:99: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def77'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def77'>[#def77]</a> >qemu-kvm-1.2.0/trace.h:105: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def78'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def78'>[#def78]</a> >qemu-kvm-1.2.0/trace.h:519: <b>bad_sizeof</b>: Taking the size of pointer parameter "sts" is suspicious. > ><a name='def79'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def79'>[#def79]</a> >qemu-kvm-1.2.0/trace.h:522: <b>bad_sizeof</b>: Taking the size of pointer parameter "schedule" is suspicious. > ><a name='def80'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def80'>[#def80]</a> >qemu-kvm-1.2.0/trace.h:522: <b>bad_sizeof</b>: Taking the size of pointer parameter "state" is suspicious. > ><a name='def81'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def81'>[#def81]</a> >qemu-kvm-1.2.0/trace.h:48: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. > ><a name='def82'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def82'>[#def82]</a> >qemu-kvm-1.2.0/trace.h:1920: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. > ><a name='def83'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def83'>[#def83]</a> >qemu-kvm-1.2.0/trace.h:1923: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. > ><a name='def84'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def84'>[#def84]</a> >qemu-kvm-1.2.0/trace.h:1914: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. > ><a name='def85'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def85'>[#def85]</a> >qemu-kvm-1.2.0/trace.h:1914: <b>bad_sizeof</b>: Taking the size of pointer parameter "evname" is suspicious. > ><a name='def86'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def86'>[#def86]</a> >qemu-kvm-1.2.0/trace.h:525: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. > ><a name='def87'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def87'>[#def87]</a> >qemu-kvm-1.2.0/trace.h:552: <b>bad_sizeof</b>: Taking the size of pointer parameter "owner" is suspicious. > ><a name='def88'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def88'>[#def88]</a> >qemu-kvm-1.2.0/trace.h:501: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. > ><a name='def89'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def89'>[#def89]</a> >qemu-kvm-1.2.0/trace.h:507: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. > ><a name='def90'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def90'>[#def90]</a> >qemu-kvm-1.2.0/trace.h:504: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. > ><a name='def91'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def91'>[#def91]</a> >qemu-kvm-1.2.0/trace.h:549: <b>bad_sizeof</b>: Taking the size of pointer parameter "device" is suspicious. > ><a name='def92'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def92'>[#def92]</a> >qemu-kvm-1.2.0/trace.h:549: <b>bad_sizeof</b>: Taking the size of pointer parameter "owner" is suspicious. > ><a name='def93'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def93'>[#def93]</a> >qemu-kvm-1.2.0/trace.h:534: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. > ><a name='def94'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def94'>[#def94]</a> >qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "action" is suspicious. > ><a name='def95'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def95'>[#def95]</a> >qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def96'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def96'>[#def96]</a> >qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. > ><a name='def97'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def97'>[#def97]</a> >qemu-kvm-1.2.0/trace.h:561: <b>bad_sizeof</b>: Taking the size of pointer parameter "action" is suspicious. > ><a name='def98'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def98'>[#def98]</a> >qemu-kvm-1.2.0/trace.h:561: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. > ><a name='def99'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def99'>[#def99]</a> >qemu-kvm-1.2.0/trace.h:570: <b>bad_sizeof</b>: Taking the size of pointer parameter "reason" is suspicious. > ><a name='def100'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def100'>[#def100]</a> >qemu-kvm-1.2.0/trace.h:87: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def101'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def101'>[#def101]</a> >qemu-kvm-1.2.0/trace.h:87: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def102'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def102'>[#def102]</a> >qemu-kvm-1.2.0/trace.h:84: <b>bad_sizeof</b>: Taking the size of pointer parameter "mcb" is suspicious. > ><a name='def103'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def103'>[#def103]</a> >qemu-kvm-1.2.0/trace.h:2400: <b>bad_sizeof</b>: Taking the size of pointer parameter "busname" is suspicious. > ><a name='def104'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def104'>[#def104]</a> >qemu-kvm-1.2.0/trace.h:2388: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def105'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def105'>[#def105]</a> >qemu-kvm-1.2.0/trace.h:2385: <b>bad_sizeof</b>: Taking the size of pointer parameter "msg" is suspicious. > ><a name='def106'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def106'>[#def106]</a> >qemu-kvm-1.2.0/trace.h:1704: <b>bad_sizeof</b>: Taking the size of pointer parameter "nxt" is suspicious. > ><a name='def107'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def107'>[#def107]</a> >qemu-kvm-1.2.0/trace.h:1707: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. > ><a name='def108'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def108'>[#def108]</a> >qemu-kvm-1.2.0/trace.h:1707: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. > ><a name='def109'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def109'>[#def109]</a> >qemu-kvm-1.2.0/trace.h:1710: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. > ><a name='def110'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def110'>[#def110]</a> >qemu-kvm-1.2.0/trace.h:1710: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. > ><a name='def111'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def111'>[#def111]</a> >qemu-kvm-1.2.0/trace.h:1713: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. > ><a name='def112'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def112'>[#def112]</a> >qemu-kvm-1.2.0/trace.h:1713: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. > ><a name='def113'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def113'>[#def113]</a> >qemu-kvm-1.2.0/trace.h:1716: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. > ><a name='def114'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def114'>[#def114]</a> >qemu-kvm-1.2.0/trace.h:1716: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. > ><a name='def115'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def115'>[#def115]</a> >qemu-kvm-1.2.0/trace.h:2295: <b>bad_sizeof</b>: Taking the size of pointer parameter "surface" is suspicious. > ><a name='def116'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def116'>[#def116]</a> >qemu-kvm-1.2.0/trace.h:1686: <b>bad_sizeof</b>: Taking the size of pointer parameter "addr" is suspicious. > ><a name='def117'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def117'>[#def117]</a> >qemu-kvm-1.2.0/trace.h:1974: <b>bad_sizeof</b>: Taking the size of pointer parameter "aname" is suspicious. > ><a name='def118'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def118'>[#def118]</a> >qemu-kvm-1.2.0/trace.h:1974: <b>bad_sizeof</b>: Taking the size of pointer parameter "uname" is suspicious. > ><a name='def119'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def119'>[#def119]</a> >qemu-kvm-1.2.0/trace.h:1125: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def120'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def120'>[#def120]</a> >qemu-kvm-1.2.0/trace.h:1125: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def121'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def121'>[#def121]</a> >qemu-kvm-1.2.0/trace.h:1122: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def122'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def122'>[#def122]</a> >qemu-kvm-1.2.0/trace.h:1122: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def123'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def123'>[#def123]</a> >qemu-kvm-1.2.0/trace.h:2034: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def124'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def124'>[#def124]</a> >qemu-kvm-1.2.0/trace.h:2049: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def125'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def125'>[#def125]</a> >qemu-kvm-1.2.0/trace.h:2076: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def126'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def126'>[#def126]</a> >qemu-kvm-1.2.0/trace.h:2094: <b>bad_sizeof</b>: Taking the size of pointer parameter "target" is suspicious. > ><a name='def127'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def127'>[#def127]</a> >qemu-kvm-1.2.0/trace.h:2040: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def128'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def128'>[#def128]</a> >qemu-kvm-1.2.0/trace.h:2040: <b>bad_sizeof</b>: Taking the size of pointer parameter "symname" is suspicious. > ><a name='def129'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def129'>[#def129]</a> >qemu-kvm-1.2.0/trace.h:1968: <b>bad_sizeof</b>: Taking the size of pointer parameter "version" is suspicious. > ><a name='def130'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def130'>[#def130]</a> >qemu-kvm-1.2.0/trace.h:1971: <b>bad_sizeof</b>: Taking the size of pointer parameter "version" is suspicious. > ><a name='def131'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def131'>[#def131]</a> >qemu-kvm-1.2.0/trace.h:1995: <b>bad_sizeof</b>: Taking the size of pointer parameter "qids" is suspicious. > ><a name='def132'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def132'>[#def132]</a> >qemu-kvm-1.2.0/trace.h:2088: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def133'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def133'>[#def133]</a> >qemu-kvm-1.2.0/trace.h:2082: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def134'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def134'>[#def134]</a> >qemu-kvm-1.2.0/trace.h:114: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def135'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def135'>[#def135]</a> >qemu-kvm-1.2.0/trace.h:114: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def136'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def136'>[#def136]</a> >qemu-kvm-1.2.0/trace.h:111: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def137'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def137'>[#def137]</a> >qemu-kvm-1.2.0/trace.h:24: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def138'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def138'>[#def138]</a> >qemu-kvm-1.2.0/trace.h:717: <b>bad_sizeof</b>: Taking the size of pointer parameter "evt" is suspicious. > ><a name='def139'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def139'>[#def139]</a> >qemu-kvm-1.2.0/trace.h:717: <b>bad_sizeof</b>: Taking the size of pointer parameter "trb" is suspicious. > ><a name='def140'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def140'>[#def140]</a> >qemu-kvm-1.2.0/trace.h:762: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def141'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def141'>[#def141]</a> >qemu-kvm-1.2.0/trace.h:774: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def142'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def142'>[#def142]</a> >qemu-kvm-1.2.0/trace.h:765: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def143'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def143'>[#def143]</a> >qemu-kvm-1.2.0/trace.h:768: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def144'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def144'>[#def144]</a> >qemu-kvm-1.2.0/trace.h:759: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def145'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def145'>[#def145]</a> >qemu-kvm-1.2.0/trace.h:18: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def146'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def146'>[#def146]</a> >qemu-kvm-1.2.0/trace.h:720: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. > ><a name='def147'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def147'>[#def147]</a> >qemu-kvm-1.2.0/trace.h:771: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. > ><a name='def148'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def148'>[#def148]</a> >qemu-kvm-1.2.0/trace.h:147: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def149'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def149'>[#def149]</a> >qemu-kvm-1.2.0/trace.h:147: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def150'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def150'>[#def150]</a> >qemu-kvm-1.2.0/trace.h:1419: <b>bad_sizeof</b>: Taking the size of pointer parameter "dcmd" is suspicious. > ><a name='def151'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def151'>[#def151]</a> >qemu-kvm-1.2.0/trace.h:1272: <b>bad_sizeof</b>: Taking the size of pointer parameter "cmd" is suspicious. > ><a name='def152'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def152'>[#def152]</a> >qemu-kvm-1.2.0/trace.h:918: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. > ><a name='def153'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def153'>[#def153]</a> >qemu-kvm-1.2.0/trace.h:912: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. > ><a name='def154'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def154'>[#def154]</a> >qemu-kvm-1.2.0/trace.h:1395: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. > ><a name='def155'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def155'>[#def155]</a> >qemu-kvm-1.2.0/trace.h:1392: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. > ><a name='def156'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def156'>[#def156]</a> >qemu-kvm-1.2.0/trace.h:960: <b>bad_sizeof</b>: Taking the size of pointer parameter "dir" is suspicious. > ><a name='def157'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def157'>[#def157]</a> >qemu-kvm-1.2.0/trace.h:960: <b>bad_sizeof</b>: Taking the size of pointer parameter "type" is suspicious. > ><a name='def158'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def158'>[#def158]</a> >qemu-kvm-1.2.0/trace.h:966: <b>bad_sizeof</b>: Taking the size of pointer parameter "errmsg" is suspicious. > ><a name='def159'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def159'>[#def159]</a> >qemu-kvm-1.2.0/trace.h:909: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def160'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def160'>[#def160]</a> >qemu-kvm-1.2.0/trace.h:897: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def161'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def161'>[#def161]</a> >qemu-kvm-1.2.0/trace.h:900: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def162'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def162'>[#def162]</a> >qemu-kvm-1.2.0/trace.h:906: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. > ><a name='def163'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def163'>[#def163]</a> >qemu-kvm-1.2.0/block/curl.c:296: <b>bad_sizeof</b>: Taking the size of "curl_read_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? > ><a name='def164'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def164'>[#def164]</a> >qemu-kvm-1.2.0/block/curl.c:390: <b>bad_sizeof</b>: Taking the size of "curl_read_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? > ><a name='def165'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def165'>[#def165]</a> >qemu-kvm-1.2.0/block/curl.c:386: <b>bad_sizeof</b>: Taking the size of "curl_size_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? > ><a name='def166'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def166'>[#def166]</a> >qemu-kvm-1.2.0/trace.h:1911: <b>bad_sizeof</b>: Taking the size of pointer parameter "mon" is suspicious. > ><a name='def167'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def167'>[#def167]</a> >qemu-kvm-1.2.0/trace.h:2202: <b>bad_sizeof</b>: Taking the size of pointer parameter "cookie" is suspicious. > ><a name='def168'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def168'>[#def168]</a> >qemu-kvm-1.2.0/trace.h:2364: <b>bad_sizeof</b>: Taking the size of pointer parameter "client_monitors_config" is suspicious. > ><a name='def169'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def169'>[#def169]</a> >qemu-kvm-1.2.0/trace.h:2361: <b>bad_sizeof</b>: Taking the size of pointer parameter "heads" is suspicious. > ><a name='def170'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def170'>[#def170]</a> >qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "last_release" is suspicious. > ><a name='def171'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def171'>[#def171]</a> >qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def172'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def172'>[#def172]</a> >qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "notify" is suspicious. > ><a name='def173'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def173'>[#def173]</a> >qemu-kvm-1.2.0/trace.h:2256: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def174'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def174'>[#def174]</a> >qemu-kvm-1.2.0/trace.h:2259: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def175'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def175'>[#def175]</a> >qemu-kvm-1.2.0/trace.h:2265: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def176'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def176'>[#def176]</a> >qemu-kvm-1.2.0/trace.h:2268: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def177'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def177'>[#def177]</a> >qemu-kvm-1.2.0/hw/qxl.c:952: <b>bad_sizeof</b>: Taking the size of pointer parameter "caps" is suspicious. > ><a name='def178'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def178'>[#def178]</a> >qemu-kvm-1.2.0/hw/qxl.c:954: <b>bad_sizeof</b>: Taking the size of pointer parameter "caps" is suspicious. > ><a name='def179'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def179'>[#def179]</a> >qemu-kvm-1.2.0/trace.h:2226: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def180'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def180'>[#def180]</a> >qemu-kvm-1.2.0/trace.h:2229: <b>bad_sizeof</b>: Taking the size of pointer parameter "log_buf" is suspicious. > ><a name='def181'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def181'>[#def181]</a> >qemu-kvm-1.2.0/trace.h:2235: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. > ><a name='def182'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def182'>[#def182]</a> >qemu-kvm-1.2.0/trace.h:2238: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def183'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def183'>[#def183]</a> >qemu-kvm-1.2.0/trace.h:2331: <b>bad_sizeof</b>: Taking the size of pointer parameter "ext" is suspicious. > ><a name='def184'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def184'>[#def184]</a> >qemu-kvm-1.2.0/trace.h:2244: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def185'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def185'>[#def185]</a> >qemu-kvm-1.2.0/trace.h:1101: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def186'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def186'>[#def186]</a> >qemu-kvm-1.2.0/trace.h:1107: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def187'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def187'>[#def187]</a> >qemu-kvm-1.2.0/trace.h:1107: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def188'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def188'>[#def188]</a> >qemu-kvm-1.2.0/trace.h:1113: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def189'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def189'>[#def189]</a> >qemu-kvm-1.2.0/trace.h:1113: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def190'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def190'>[#def190]</a> >qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def191'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def191'>[#def191]</a> >qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def192'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def192'>[#def192]</a> >qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def193'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def193'>[#def193]</a> >qemu-kvm-1.2.0/trace.h:1104: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def194'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def194'>[#def194]</a> >qemu-kvm-1.2.0/trace.h:1344: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def195'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def195'>[#def195]</a> >qemu-kvm-1.2.0/trace.h:1347: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def196'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def196'>[#def196]</a> >qemu-kvm-1.2.0/trace.h:1311: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def197'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def197'>[#def197]</a> >qemu-kvm-1.2.0/trace.h:1326: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def198'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def198'>[#def198]</a> >qemu-kvm-1.2.0/trace.h:1305: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def199'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def199'>[#def199]</a> >qemu-kvm-1.2.0/trace.h:1305: <b>bad_sizeof</b>: Taking the size of pointer parameter "sdev" is suspicious. > ><a name='def200'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def200'>[#def200]</a> >qemu-kvm-1.2.0/trace.h:1308: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. > ><a name='def201'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def201'>[#def201]</a> >qemu-kvm-1.2.0/trace.h:126: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. > ><a name='def202'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def202'>[#def202]</a> >qemu-kvm-1.2.0/trace.h:132: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def203'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def203'>[#def203]</a> >qemu-kvm-1.2.0/trace.h:132: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. > ><a name='def204'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def204'>[#def204]</a> >qemu-kvm-1.2.0/trace.h:129: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def205'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def205'>[#def205]</a> >qemu-kvm-1.2.0/trace.h:129: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. > ><a name='def206'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def206'>[#def206]</a> >qemu-kvm-1.2.0/trace.h:1044: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def207'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def207'>[#def207]</a> >qemu-kvm-1.2.0/trace.h:1056: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def208'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def208'>[#def208]</a> >qemu-kvm-1.2.0/trace.h:1047: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def209'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def209'>[#def209]</a> >qemu-kvm-1.2.0/trace.h:1053: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def210'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def210'>[#def210]</a> >qemu-kvm-1.2.0/trace.h:1050: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def211'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def211'>[#def211]</a> >qemu-kvm-1.2.0/trace.h:2175: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. > ><a name='def212'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def212'>[#def212]</a> >qemu-kvm-1.2.0/trace.h:2175: <b>bad_sizeof</b>: Taking the size of pointer parameter "filename" is suspicious. > ><a name='def213'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def213'>[#def213]</a> >qemu-kvm-1.2.0/trace.h:93: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def214'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def214'>[#def214]</a> >qemu-kvm-1.2.0/trace.h:93: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def215'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def215'>[#def215]</a> >qemu-kvm-1.2.0/trace.h:96: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def216'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def216'>[#def216]</a> >qemu-kvm-1.2.0/trace.h:96: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def217'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def217'>[#def217]</a> >qemu-kvm-1.2.0/trace.h:1071: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def218'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def218'>[#def218]</a> >qemu-kvm-1.2.0/trace.h:1074: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def219'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def219'>[#def219]</a> >qemu-kvm-1.2.0/trace.h:1059: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def220'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def220'>[#def220]</a> >qemu-kvm-1.2.0/trace.h:1068: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def221'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def221'>[#def221]</a> >qemu-kvm-1.2.0/trace.h:1065: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def222'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def222'>[#def222]</a> >qemu-kvm-1.2.0/trace.h:1062: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def223'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def223'>[#def223]</a> >qemu-kvm-1.2.0/trace.h:1086: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def224'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def224'>[#def224]</a> >qemu-kvm-1.2.0/trace.h:1086: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. > ><a name='def225'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def225'>[#def225]</a> >qemu-kvm-1.2.0/trace.h:1092: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def226'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def226'>[#def226]</a> >qemu-kvm-1.2.0/trace.h:1092: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. > ><a name='def227'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def227'>[#def227]</a> >qemu-kvm-1.2.0/trace.h:1089: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def228'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def228'>[#def228]</a> >qemu-kvm-1.2.0/trace.h:1089: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. > ><a name='def229'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def229'>[#def229]</a> >qemu-kvm-1.2.0/trace.h:1095: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def230'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def230'>[#def230]</a> >qemu-kvm-1.2.0/trace.h:1095: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. > ><a name='def231'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def231'>[#def231]</a> >qemu-kvm-1.2.0/trace.h:1197: <b>bad_sizeof</b>: Taking the size of pointer parameter "scd" is suspicious. > ><a name='def232'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def232'>[#def232]</a> >qemu-kvm-1.2.0/trace.h:1194: <b>bad_sizeof</b>: Taking the size of pointer parameter "scd" is suspicious. > ><a name='def233'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def233'>[#def233]</a> >qemu-kvm-1.2.0/trace.h:1038: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def234'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def234'>[#def234]</a> >qemu-kvm-1.2.0/trace.h:1035: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def235'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def235'>[#def235]</a> >qemu-kvm-1.2.0/trace.h:1041: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def236'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def236'>[#def236]</a> >qemu-kvm-1.2.0/trace.h:1032: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def237'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def237'>[#def237]</a> >qemu-kvm-1.2.0/trace.h:33: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def238'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def238'>[#def238]</a> >qemu-kvm-1.2.0/trace.h:27: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def239'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def239'>[#def239]</a> >qemu-kvm-1.2.0/trace.h:30: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. > ><a name='def240'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def240'>[#def240]</a> >qemu-kvm-1.2.0/trace.h:2382: <b>bad_sizeof</b>: Taking the size of pointer parameter "cookie" is suspicious. > ><a name='def241'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def241'>[#def241]</a> >qemu-kvm-1.2.0/trace.h:81: <b>bad_sizeof</b>: Taking the size of pointer parameter "mcb" is suspicious. > ><a name='def242'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def242'>[#def242]</a> >qemu-kvm-1.2.0/trace.h:1917: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. > ><a name='def243'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def243'>[#def243]</a> >qemu-kvm-1.2.0/trace.h:153: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def244'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def244'>[#def244]</a> >qemu-kvm-1.2.0/trace.h:153: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def245'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def245'>[#def245]</a> >qemu-kvm-1.2.0/trace.h:150: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. > ><a name='def246'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def246'>[#def246]</a> >qemu-kvm-1.2.0/trace.h:150: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def247'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def247'>[#def247]</a> >qemu-kvm-1.2.0/block/rbd.c:593: <b>bad_sizeof</b>: Taking the size of pointer parameter "rcb" is suspicious. > ><a name='def248'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def248'>[#def248]</a> >qemu-kvm-1.2.0/trace.h:120: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def249'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def249'>[#def249]</a> >qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "base" is suspicious. > ><a name='def250'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def250'>[#def250]</a> >qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def251'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def251'>[#def251]</a> >qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def252'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def252'>[#def252]</a> >qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def253'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def253'>[#def253]</a> >qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def254'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def254'>[#def254]</a> >qemu-kvm-1.2.0/trace.h:162: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def255'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def255'>[#def255]</a> >qemu-kvm-1.2.0/trace.h:1077: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. > ><a name='def256'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def256'>[#def256]</a> >qemu-kvm-1.2.0/trace.h:1077: <b>bad_sizeof</b>: Taking the size of pointer parameter "l2_cache" is suspicious. > ><a name='def257'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def257'>[#def257]</a> >qemu-kvm-1.2.0/trace.h:1083: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. > ><a name='def258'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def258'>[#def258]</a> >qemu-kvm-1.2.0/trace.h:1083: <b>bad_sizeof</b>: Taking the size of pointer parameter "l2_cache" is suspicious. > ><a name='def259'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def259'>[#def259]</a> >qemu-kvm-1.2.0/trace.h:1080: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. > ><a name='def260'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def260'>[#def260]</a> >qemu-kvm-1.2.0/trace.h:1098: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. > ><a name='def261'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def261'>[#def261]</a> >qemu-kvm-1.2.0/trace.h:1698: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. > ><a name='def262'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def262'>[#def262]</a> >qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "from" is suspicious. > ><a name='def263'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def263'>[#def263]</a> >qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. > ><a name='def264'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def264'>[#def264]</a> >qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "to" is suspicious. > ><a name='def265'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def265'>[#def265]</a> >qemu-kvm-1.2.0/trace.h:1695: <b>bad_sizeof</b>: Taking the size of pointer parameter "from" is suspicious. > ><a name='def266'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def266'>[#def266]</a> >qemu-kvm-1.2.0/trace.h:1695: <b>bad_sizeof</b>: Taking the size of pointer parameter "to" is suspicious. > ><a name='def267'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def267'>[#def267]</a> >qemu-kvm-1.2.0/trace.h:1458: <b>bad_sizeof</b>: Taking the size of pointer parameter "intr" is suspicious. > ><a name='def268'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def268'>[#def268]</a> >qemu-kvm-1.2.0/trace.h:1458: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. > ><a name='def269'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def269'>[#def269]</a> >qemu-kvm-1.2.0/trace.h:264: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def270'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def270'>[#def270]</a> >qemu-kvm-1.2.0/trace.h:267: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. > ><a name='def271'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE</span> (CWE-170):</b> <a href ='#def271'>[#def271]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_true</b>: Condition "is_dot", taking true branch</span> >qemu-kvm-1.2.0/block/vvfat.c:622: <b>buffer_size</b>: You might overrun the 8 byte destination string "entry->name" by writing the maximum 11 bytes from "32". > ><a name='def272'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE</span> (CWE-170):</b> <a href ='#def272'>[#def272]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_false</b>: Condition "is_dot", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:625: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "filename[j] != '.'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_false</b>: Condition "filename[j] != '.'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:631: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>cond_true</b>: Condition "j > 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:634: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block/vvfat.c:637: <b>buffer_size</b>: You might overrun the 8 byte destination string "entry->name" by writing the maximum 11 bytes from "32". > ><a name='def273'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def273'>[#def273]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1178: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1180: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block/sheepdog.c:1183: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "buf" of size 256 bytes might leave the destination string unterminated. > ><a name='def274'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def274'>[#def274]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:1390: <b>cond_true</b>: Condition "hci->device.lmp_name", taking true branch</span> >qemu-kvm-1.2.0/hw/bt-hci.c:1391: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 248 bytes on destination array "params.name" of size 248 bytes might leave the destination string unterminated. > ><a name='def275'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def275'>[#def275]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2451: <b>cond_true</b>: Condition "len >= 80", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2453: <b>cond_false</b>: Condition "copy_from_user(&psinfo->pr_psargs, ts->info->arg_start, len)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2454: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_true</b>: Condition "i < len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2456: <b>cond_true</b>: Condition "psinfo->pr_psargs[i] == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_true</b>: Condition "i < len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2456: <b>cond_true</b>: Condition "psinfo->pr_psargs[i] == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_false</b>: Condition "i < len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2467: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2468: <b>cond_false</b>: Condition "0", taking false branch</span> >qemu-kvm-1.2.0/linux-user/elfload.c:2469: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "psinfo->pr_fname" of size 16 bytes might leave the destination string unterminated. > ><a name='def276'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def276'>[#def276]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:108: <b>cond_false</b>: Condition "!v9fs_synth_fs", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:110: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:111: <b>cond_false</b>: Condition "!name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:111: <b>cond_false</b>: Condition "strlen(name) >= 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:113: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:114: <b>cond_true</b>: Condition "!parent", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>cond_true</b>: Condition "tmp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:120: <b>cond_false</b>: Condition "!__coverity_strcmp(tmp->name, name)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:123: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:124: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>cond_false</b>: Condition "tmp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:124: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:135: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 255 bytes on destination array "node->name" of size 255 bytes might leave the destination string unterminated.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:136: <b>cond_true</b>: Condition "parent->child.lh_first != NULL", taking true branch > ><a name='def277'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def277'>[#def277]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:47: <b>cond_true</b>: Condition "attr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:51: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:59: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:61: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 255 bytes on destination array "node->name" of size 255 bytes might leave the destination string unterminated.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:62: <b>cond_true</b>: Condition "parent->child.lh_first != NULL", taking true branch > ><a name='def278'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def278'>[#def278]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1280: <b>cond_false</b>: Condition "!drv", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1283: <b>cond_false</b>: Condition "!bs->backing_hd", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1285: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1287: <b>cond_false</b>: Condition "bs->backing_hd->keep_read_only", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1291: <b>cond_false</b>: Condition "bdrv_in_use(bs)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1291: <b>cond_false</b>: Condition "bdrv_in_use(bs->backing_hd)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1293: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1297: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 1024 bytes on destination array "filename" of size 1024 bytes might leave the destination string unterminated.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1300: <b>cond_true</b>: Condition "ro", taking true branch</span> >qemu-kvm-1.2.0/block.c:1307: <b>cond_true</b>: Condition "rw_ret < 0", taking true branch > ><a name='def279'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def279'>[#def279]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1102: <b>cond_false</b>: Condition "parse_vdiname(s, filename, vdi, &snapid, tag) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1105: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1107: <b>cond_false</b>: Condition "s->fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1110: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1113: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1115: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1117: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1120: <b>cond_false</b>: Condition "s->flush_fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1124: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1127: <b>cond_true</b>: Condition "snapid", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1133: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1137: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1145: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1147: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block/sheepdog.c:1154: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "s->name" of size 256 bytes might leave the destination string unterminated. > ><a name='def280'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def280'>[#def280]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1746: <b>cond_false</b>: Condition "s->is_snapshot", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1757: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "s->inode.tag" of size 256 bytes might leave the destination string unterminated.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1763: <b>cond_true</b>: Condition "fd < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1765: <b>goto</b>: Jumping to label "cleanup"</span> >qemu-kvm-1.2.0/block/sheepdog.c:1797: <b>label</b>: Reached label "cleanup" > ><a name='def281'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def281'>[#def281]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1821: <b>cond_true</b>: Condition "!snapid", taking true branch</span> >qemu-kvm-1.2.0/block/sheepdog.c:1822: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "tag" of size 256 bytes might leave the destination string unterminated. > ><a name='def282'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def282'>[#def282]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1817: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "vdi" of size 256 bytes might leave the destination string unterminated.</span> >qemu-kvm-1.2.0/block/sheepdog.c:1821: <b>cond_true</b>: Condition "!snapid", taking true branch > ><a name='def283'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def283'>[#def283]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1896: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1899: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1912: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1914: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1923: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1927: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_false</b>: Condition "!test_bit(vid, vdi_inuse)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1932: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1939: <b>cond_true</b>: Condition "ret", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1940: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_false</b>: Condition "!test_bit(vid, vdi_inuse)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1932: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1939: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1941: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1943: <b>cond_true</b>: Condition "!__coverity_strcmp(inode.name, s->name)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1943: <b>cond_true</b>: Condition "is_snapshot(&inode)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1951: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "(sn_tab + found).name" of size 256 bytes might leave the destination string unterminated.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_true</b>: Condition "!test_bit(vid, vdi_inuse)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1931: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1963: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> >qemu-kvm-1.2.0/block/sheepdog.c:1965: <b>if_end</b>: End of if statement > ><a name='def284'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def284'>[#def284]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:149: <b>cond_false</b>: Condition "!s", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:150: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:152: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "name" of size 16 bytes might leave the destination string unterminated.</span> >qemu-kvm-1.2.0/os-posix.c:155: <b>cond_true</b>: Condition "prctl(15, name)", taking true branch > ><a name='def285'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def285'>[#def285]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:239: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:244: <b>cond_false</b>: Condition "cpu == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:247: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:283: <b>cond_true</b>: Condition "dinfo", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_true</b>: Condition "i < nb_nics", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>cond_true</b>: Condition "i == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_true</b>: Condition "i < nb_nics", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>cond_false</b>: Condition "i == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_false</b>: Condition "i < nb_nics", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:299: <b>cond_true</b>: Condition "kernel_filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:305: <b>cond_false</b>: Condition "kernel_size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:308: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:316: <b>cond_true</b>: Condition "initrd_filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:323: <b>cond_false</b>: Condition "initrd_size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:326: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:334: <b>cond_true</b>: Condition "kernel_cmdline", taking true branch</span> >qemu-kvm-1.2.0/hw/r2d.c:335: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "boot_params.kernel_cmdline" of size 256 bytes might leave the destination string unterminated. > ><a name='def286'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def286'>[#def286]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:831: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "ifr.ifr_ifrn.ifrn_name" of size 16 bytes might leave the destination string unterminated.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_true</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>goto</b>: Jumping to label "error"</span> >qemu-kvm-1.2.0/qga/commands-posix.c:932: <b>label</b>: Reached label "error" > ><a name='def287'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def287'>[#def287]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:165: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:175: <b>switch_default</b>: Reached default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:176: <b>check_return</b>: Calling function "audio_bug(char const *, int)" without checking return value (as is done elsewhere 25 out of 26 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:192: <b>example_checked</b>: "audio_bug("audio_calloc", cond)" has its value checked in "audio_bug("audio_calloc", cond)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1003: <b>example_checked</b>: "audio_bug(<anonymous>, live < 0 || live > hw->samples)" has its value checked in "audio_bug(<anonymous>, live < 0 || live > hw->samples)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1530: <b>example_checked</b>: "audio_bug(<anonymous>, captured > sw->total_hw_samples_mixed)" has its value checked in "audio_bug(<anonymous>, captured > sw->total_hw_samples_mixed)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1281: <b>example_checked</b>: "audio_bug(<anonymous>, live < 0 || live > sw->hw->samples)" has its value checked in "audio_bug(<anonymous>, live < 0 || live > sw->hw->samples)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/sdlaudio.c:256: <b>example_checked</b>: "audio_bug(<anonymous>, sdl->live < 0 || sdl->live > hw->samples)" has its value checked in "audio_bug(<anonymous>, sdl->live < 0 || sdl->live > hw->samples)".</span> >qemu-kvm-1.2.0/audio/audio.c:176: <b>unchecked_value</b>: No check of the return value of "audio_bug("bits_to_index", 1)". > ><a name='def288'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def288'>[#def288]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:162: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:164: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:166: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:166: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 0UL, 0, "dd", &header.type, &header.size)". > ><a name='def289'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def289'>[#def289]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:162: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:164: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:171: <b>cond_false</b>: Condition "header.size > 65536U /* 64 * 1024 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:183: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:187: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:189: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:192: <b>cond_false</b>: Condition "header.type == T_ERROR", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:199: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:201: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:246: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:247: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:247: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 8UL, 0, "q", response)". > ><a name='def290'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def290'>[#def290]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:271: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:273: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:275: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:275: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 0UL, 0, "dd", &header.type, &header.size)". > ><a name='def291'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def291'>[#def291]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:271: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:273: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:276: <b>cond_false</b>: Condition "header.size != 4UL /* sizeof (int) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:279: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:282: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:286: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:286: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)". > ><a name='def292'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def292'>[#def292]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:505: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:507: <b>cond_false</b>: Condition "err == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:509: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:512: <b>cond_true</b>: Condition "err == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:514: <b>goto</b>: Jumping to label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:541: <b>label</b>: Reached label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:542: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:542: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". > ><a name='def293'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def293'>[#def293]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:445: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:448: <b>cond_false</b>: Condition "err == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:450: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:452: <b>cond_true</b>: Condition "err == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:454: <b>goto</b>: Jumping to label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:483: <b>label</b>: Reached label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:484: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:484: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". > ><a name='def294'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def294'>[#def294]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:609: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:611: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:614: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:618: <b>cond_true</b>: Condition "err == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:620: <b>goto</b>: Jumping to label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:652: <b>label</b>: Reached label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:654: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:654: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". > ><a name='def295'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def295'>[#def295]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:676: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:681: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:684: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:689: <b>cond_false</b>: Condition "write_size == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:691: <b>cond_false</b>: Condition "write_size != oldpath_size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:696: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:701: <b>cond_true</b>: Condition "err == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:703: <b>goto</b>: Jumping to label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:756: <b>label</b>: Reached label "err_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:757: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, newpath, buffer))" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:757: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, newpath, buffer))". > ><a name='def296'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def296'>[#def296]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "267U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:204: <b>switch_case</b>: Reached case "267U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:207: <b>cond_false</b>: Condition "e.a_text + e.a_data > max_sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:208: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:209: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:209: <b>check_return</b>: Calling function "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/loader.c:209: <b>unchecked_value</b>: No check of the return value of "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)". > ><a name='def297'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def297'>[#def297]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>check_return</b>: Calling function "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/loader.c:217: <b>unchecked_value</b>: No check of the return value of "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)". > ><a name='def298'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def298'>[#def298]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>check_return</b>: Calling function "lseek(fd, ehdr.e_phoff, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>unchecked_value</b>: No check of the return value of "lseek(fd, ehdr.e_phoff, 0)". > ><a name='def299'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def299'>[#def299]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>check_return</b>: Calling function "lseek(fd, ehdr.e_phoff, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>unchecked_value</b>: No check of the return value of "lseek(fd, ehdr.e_phoff, 0)". > ><a name='def300'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def300'>[#def300]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2764: <b>cond_false</b>: Condition "dumpsize.rlim_cur == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2765: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2767: <b>cond_false</b>: Condition "core_dump_filename(ts, corefile, 4096UL /* sizeof (corefile) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2768: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2770: <b>cond_false</b>: Condition "(fd = open(corefile, 65 /* 1 | 0x40 */, 420 /* ((0x100 | 0x80) | (0x100 >> 3)) | ((0x100 >> 3) >> 3) */)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2772: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2779: <b>cond_false</b>: Condition "(mm = vma_init()) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2780: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2790: <b>cond_false</b>: Condition "dump_write(fd, &elf, 52UL /* sizeof (elf) */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2791: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2794: <b>cond_false</b>: Condition "fill_note_info(&info, signr, env) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2795: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2804: <b>cond_false</b>: Condition "dump_write(fd, &phdr, 32UL /* sizeof (phdr) */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2805: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2811: <b>cond_true</b>: Condition "1 /* 1 && (8192 - 1 & 0x2000) == 0 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2817: <b>cond_true</b>: Condition "vma != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2827: <b>cond_true</b>: Condition "vma->vma_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2828: <b>cond_true</b>: Condition "vma->vma_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2830: <b>cond_true</b>: Condition "vma->vma_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2835: <b>check_return</b>: Calling function "dump_write(int, void const *, size_t)" without checking return value (as is done elsewhere 6 out of 7 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2591: <b>example_checked</b>: "dump_write(fd, &en, 12UL)" has its value checked in "dump_write(fd, &en, 12UL) != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2593: <b>example_checked</b>: "dump_write(fd, men->name, men->namesz_rounded)" has its value checked in "dump_write(fd, men->name, men->namesz_rounded) != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2595: <b>example_checked</b>: "dump_write(fd, men->data, men->datasz_rounded)" has its value checked in "dump_write(fd, men->data, men->datasz_rounded) != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2790: <b>example_checked</b>: "dump_write(fd, &elf, 52UL)" has its value checked in "dump_write(fd, &elf, 52UL) != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2804: <b>example_checked</b>: "dump_write(fd, &phdr, 32UL)" has its value checked in "dump_write(fd, &phdr, 32UL) != 0".</span> >qemu-kvm-1.2.0/linux-user/elfload.c:2835: <b>unchecked_value</b>: No check of the return value of "dump_write(fd, &phdr, 32UL)". > ><a name='def301'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def301'>[#def301]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:525: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_BRIDGE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:528: <b>cond_true</b>: Condition "bridge->has_helper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:529: <b>cond_true</b>: Condition "bridge->has_br", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:532: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:534: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:536: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/net/tap.c:536: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". > ><a name='def302'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def302'>[#def302]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:602: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_TAP", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:605: <b>cond_true</b>: Condition "tap->has_fd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_ifname", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_script", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_downscript", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_vnet_hdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_helper", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:611: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:614: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:616: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:618: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/net/tap.c:618: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". > ><a name='def303'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def303'>[#def303]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:602: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_TAP", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:605: <b>cond_false</b>: Condition "tap->has_fd", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:624: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:624: <b>cond_true</b>: Condition "tap->has_helper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_ifname", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_script", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_downscript", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_vnet_hdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:630: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:633: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:635: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:637: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/net/tap.c:637: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". > ><a name='def304'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def304'>[#def304]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2468: <b>check_return</b>: Calling function "setsockopt(fd, 6, 1, (char *)&val, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:2468: <b>unchecked_value</b>: No check of the return value of "setsockopt(fd, 6, 1, (char *)&val, 4U)". > ><a name='def305'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def305'>[#def305]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2456: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:2456: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". > ><a name='def306'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def306'>[#def306]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2458: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:2458: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". > ><a name='def307'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def307'>[#def307]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2460: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:2460: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". > ><a name='def308'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def308'>[#def308]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2462: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:2462: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". > ><a name='def309'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def309'>[#def309]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:858: <b>cond_false</b>: Condition "stdio_nb_clients >= 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:860: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:861: <b>cond_true</b>: Condition "stdio_nb_clients == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:864: <b>check_return</b>: Calling function "fcntl(0, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:864: <b>unchecked_value</b>: No check of the return value of "fcntl(0, 4, 2048)". > ><a name='def310'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def310'>[#def310]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1095: <b>check_return</b>: Calling function "fd_open(BlockDriverState *)" without checking return value (as is done elsewhere 6 out of 7 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1083: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) >= 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:941: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:369: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:325: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:612: <b>example_assign</b>: Assigning: "ret" = return value from "fd_open(bs)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:613: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> >qemu-kvm-1.2.0/block/raw-posix.c:1095: <b>unchecked_value</b>: No check of the return value of "fd_open(bs)". > ><a name='def311'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def311'>[#def311]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:324: <b>check_return</b>: Calling function "fstat(fd, &buf)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/ivshmem.c:324: <b>unchecked_value</b>: No check of the return value of "fstat(fd, &buf)". > ><a name='def312'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def312'>[#def312]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:660: <b>check_return</b>: Calling function "fseek(f, where, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/pc.c:660: <b>unchecked_value</b>: No check of the return value of "fseek(f, where, 0)". > ><a name='def313'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def313'>[#def313]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi01.c:203: <b>cond_true</b>: Condition "pfl->bs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi01.c:208: <b>check_return</b>: Calling function "bdrv_write(BlockDriverState *, int64_t, uint8_t const *, int)" without checking return value (as is done elsewhere 36 out of 40 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:813: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs, sector_num, buf, s->cluster_sectors)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:814: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1161: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, (meta.cluster_offset >> 9) + num - 1UL, buf, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1162: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:596: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, 0L, block, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:600: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:761: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(extent->file, cluster_offset, whole_grain, extent->cluster_sectors)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:763: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1697: <b>example_checked</b>: "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)" has its value checked in "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)".</span> >qemu-kvm-1.2.0/hw/pflash_cfi01.c:208: <b>unchecked_value</b>: No check of the return value of "bdrv_write(pfl->bs, offset, pfl->storage + (offset << 9), offset_end - offset)". > ><a name='def314'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def314'>[#def314]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:234: <b>cond_true</b>: Condition "pfl->bs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:239: <b>check_return</b>: Calling function "bdrv_write(BlockDriverState *, int64_t, uint8_t const *, int)" without checking return value (as is done elsewhere 36 out of 40 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:813: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs, sector_num, buf, s->cluster_sectors)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:814: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1161: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, (meta.cluster_offset >> 9) + num - 1UL, buf, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1162: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:596: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, 0L, block, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:600: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:761: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(extent->file, cluster_offset, whole_grain, extent->cluster_sectors)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:763: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1697: <b>example_checked</b>: "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)" has its value checked in "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)".</span> >qemu-kvm-1.2.0/hw/pflash_cfi02.c:239: <b>unchecked_value</b>: No check of the return value of "bdrv_write(pfl->bs, offset, pfl->storage + (offset << 9), offset_end - offset)". > ><a name='def315'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def315'>[#def315]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:956: <b>cond_true</b>: Condition "!nr_copies", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:962: <b>cond_true</b>: Condition "aiocb_type == AIOCB_READ_UDATA", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:966: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:974: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:976: <b>cond_true</b>: Condition "s->cache_enabled", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:997: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1001: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1003: <b>cond_false</b>: Condition "wlen", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1010: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1012: <b>check_return</b>: Calling function "socket_set_cork(s->fd, 0)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> >qemu-kvm-1.2.0/block/sheepdog.c:1012: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(s->fd, 0)". > ><a name='def316'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def316'>[#def316]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:956: <b>cond_true</b>: Condition "!nr_copies", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:962: <b>cond_true</b>: Condition "aiocb_type == AIOCB_READ_UDATA", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:966: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:974: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:976: <b>cond_true</b>: Condition "s->cache_enabled", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:993: <b>check_return</b>: Calling function "socket_set_cork(s->fd, 1)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> >qemu-kvm-1.2.0/block/sheepdog.c:993: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(s->fd, 1)". > ><a name='def317'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def317'>[#def317]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:163: <b>cond_true</b>: Condition "!done", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:163: <b>cond_false</b>: Condition "i < ncmdline", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:187: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:188: <b>cond_false</b>: Condition "cmdline", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:191: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:193: <b>cond_true</b>: Condition "!done", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:194: <b>cond_true</b>: Condition "!prompted", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:201: <b>check_return</b>: Calling function "main_loop_wait(0)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:478:5: <b>cond_true</b>: Condition "nonblocking", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:480:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:482:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:496:5: <b>return_wrapper</b>: The function wraps and returns the value of "os_host_main_loop_wait(timeout)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:298:5: <b>cond_true</b>: Condition "timeout < 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:304:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:308:5: <b>return_wrapper</b>: The function wraps and returns the value of "select(nfds + 1, &rfds, &wfds, &xfds, tvarg)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:310:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:499:5: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> >qemu-kvm-1.2.0/cmd.c:201: <b>unchecked_value</b>: No check of the return value of "main_loop_wait(0)". > ><a name='def318'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def318'>[#def318]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:514: <b>cond_false</b>: Condition "parse_host_port(&saddr, host_str) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:515: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:518: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:521: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:526: <b>check_return</b>: Calling function "setsockopt(fd, 1, 2, (char const *)&val, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/net/socket.c:526: <b>unchecked_value</b>: No check of the return value of "setsockopt(fd, 1, 2, (char const *)&val, 4U)". > ><a name='def319'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def319'>[#def319]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:431: <b>cond_true</b>: Condition "!(env->psw.mask & 0x100000000ULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:435: <b>check_return</b>: Calling function "mmu_translate(CPUS390XState *, target_ulong, int, uint64_t, target_ulong *, int *)" without checking return value (as is done elsewhere 7 out of 8 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:400: <b>example_checked</b>: "mmu_translate(env, vaddr, rw, asc, &raddr, &prot)" has its value checked in "mmu_translate(env, vaddr, rw, asc, &raddr, &prot)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:117: <b>example_checked</b>: "mmu_translate(env, src, 0, asc, &src_phys, &flags)" has its value checked in "mmu_translate(env, src, 0, asc, &src_phys, &flags)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:87: <b>example_checked</b>: "mmu_translate(env, dest, 1, asc, &dest_phys, &flags)" has its value checked in "mmu_translate(env, dest, 1, asc, &dest_phys, &flags)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:1183: <b>example_checked</b>: "mmu_translate(env, addr, 0, asc, &ret, &flags)" has its value checked in "mmu_translate(env, addr, 0, asc, &ret, &flags)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:1090: <b>example_checked</b>: "mmu_translate(env, a1 & 0xfffffffffffff000UL, 1, mode1, &dest, &flags)" has its value checked in "mmu_translate(env, a1 & 0xfffffffffffff000UL, 1, mode1, &dest, &flags)".</span> >qemu-kvm-1.2.0/target-s390x/helper.c:435: <b>unchecked_value</b>: No check of the return value of "mmu_translate(env, vaddr, 2, asc, &raddr, &prot)". > ><a name='def320'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def320'>[#def320]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:413: <b>check_return</b>: Calling function "fcntl(card->pipe[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/ccid-card-emulated.c:413: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[0], 4, 2048)". > ><a name='def321'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def321'>[#def321]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:415: <b>check_return</b>: Calling function "fcntl(card->pipe[0], 8, getpid())" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/ccid-card-emulated.c:415: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[0], 8, getpid())". > ><a name='def322'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def322'>[#def322]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:414: <b>check_return</b>: Calling function "fcntl(card->pipe[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/ccid-card-emulated.c:414: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[1], 4, 2048)". > ><a name='def323'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def323'>[#def323]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:646: <b>cond_false</b>: Condition "posix_aio_state", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:647: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:652: <b>cond_false</b>: Condition "qemu_pipe(fds) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:656: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:661: <b>check_return</b>: Calling function "fcntl(s->rfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/posix-aio-compat.c:661: <b>unchecked_value</b>: No check of the return value of "fcntl(s->rfd, 4, 2048)". > ><a name='def324'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def324'>[#def324]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:646: <b>cond_false</b>: Condition "posix_aio_state", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:647: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:652: <b>cond_false</b>: Condition "qemu_pipe(fds) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:656: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:662: <b>check_return</b>: Calling function "fcntl(s->wfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/posix-aio-compat.c:662: <b>unchecked_value</b>: No check of the return value of "fcntl(s->wfd, 4, 2048)". > ><a name='def325'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def325'>[#def325]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:821: <b>check_return</b>: Calling function "fcntl(0, 4, old_fd0_flags)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-char.c:821: <b>unchecked_value</b>: No check of the return value of "fcntl(0, 4, old_fd0_flags)". > ><a name='def326'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def326'>[#def326]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1712: <b>check_return</b>: Calling function "fcntl(d->pipe[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/qxl.c:1712: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[0], 4, 2048)". > ><a name='def327'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def327'>[#def327]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1714: <b>check_return</b>: Calling function "fcntl(d->pipe[0], 8, getpid())" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/qxl.c:1714: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[0], 8, getpid())". > ><a name='def328'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def328'>[#def328]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1713: <b>check_return</b>: Calling function "fcntl(d->pipe[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/qxl.c:1713: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[1], 4, 2048)". > ><a name='def329'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def329'>[#def329]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:356: <b>check_return</b>: Calling function "fseek(s->stdio_file, pos, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/savevm.c:356: <b>unchecked_value</b>: No check of the return value of "fseek(s->stdio_file, pos, 0)". > ><a name='def330'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def330'>[#def330]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:349: <b>check_return</b>: Calling function "fseek(s->stdio_file, pos, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/savevm.c:349: <b>unchecked_value</b>: No check of the return value of "fseek(s->stdio_file, pos, 0)". > ><a name='def331'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def331'>[#def331]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:91: <b>cond_true</b>: Condition "req", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:91: <b>cond_true</b>: Condition "(next = req->next.tqe_next) , 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:93: <b>cond_true</b>: Condition "req->retry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:95: <b>switch</b>: Switch case value "SCSI_XFER_NONE"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:100: <b>switch_case</b>: Reached case "SCSI_XFER_NONE"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:101: <b>cond_true</b>: Condition "!req->sg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:103: <b>check_return</b>: Calling function "scsi_req_enqueue(SCSIRequest *)" without checking return value (as is done elsewhere 9 out of 11 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:133: <b>example_assign</b>: Assigning: "datalen" = return value from "scsi_req_enqueue(s->current_req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:135: <b>example_checked</b>: "datalen" has its value checked in "datalen != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:773: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(s->current->req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:774: <b>example_checked</b>: "n" has its value checked in "n".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1123: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1124: <b>example_checked</b>: "len" has its value checked in "len > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:624: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(req->sreq)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:629: <b>example_checked</b>: "n" has its value checked in "n".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:560: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req->req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:561: <b>example_checked</b>: "len" has its value checked in "len".</span> >qemu-kvm-1.2.0/hw/scsi-bus.c:103: <b>unchecked_value</b>: No check of the return value of "scsi_req_enqueue(req)". > ><a name='def332'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def332'>[#def332]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "setsockopt(s, 1, 2, (char *)&opt, 4U /* sizeof (int) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), 16U /* sizeof (addr) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:643: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:646: <b>check_return</b>: Calling function "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/socket.c:646: <b>unchecked_value</b>: No check of the return value of "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". > ><a name='def333'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def333'>[#def333]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "setsockopt(s, 1, 2, (char *)&opt, 4U /* sizeof (int) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), 16U /* sizeof (addr) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:643: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:644: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/socket.c:644: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". > ><a name='def334'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def334'>[#def334]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:355: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:356: <b>check_return</b>: Calling function "sosendoob(so)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298:2: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301:2: <b>cond_true</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:303:3: <b>return_wrapper</b>: The function wraps and returns the value of "slirp_send(so, sb->sb_rptr, so->so_urgc, 1)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_false</b>: Condition "so->extra", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831:2: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:833:2: <b>return_wrapper</b>: The function wraps and returns the value of "send(so->s, buf, len, flags)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307:2: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:330:2: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:334:2: <b>cond_true</b>: Condition "sb->sb_rptr >= sb->sb_data + sb->sb_datalen", taking true branch</span> >qemu-kvm-1.2.0/slirp/socket.c:356: <b>unchecked_value</b>: No check of the return value of "sosendoob(so)". > ><a name='def335'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def335'>[#def335]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1223: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1226: <b>cond_false</b>: Condition "flat", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1236: <b>cond_true</b>: Condition "compress", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1238: <b>cond_true</b>: Condition "compress", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1277: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (magic) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1280: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1282: <b>cond_false</b>: Condition "ret != 75UL /* sizeof (header) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1285: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1288: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1291: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_true</b>: Condition "i < gt_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1298: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (tmp) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1301: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_true</b>: Condition "i < gt_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1298: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (tmp) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1301: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_false</b>: Condition "i < gt_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1305: <b>check_return</b>: Calling function "lseek(fd, le64_to_cpu(header.gd_offset) << 9, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/block/vmdk.c:1305: <b>unchecked_value</b>: No check of the return value of "lseek(fd, le64_to_cpu(header.gd_offset) << 9, 0)". > ><a name='def336'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def336'>[#def336]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1223: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1226: <b>cond_false</b>: Condition "flat", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1236: <b>cond_true</b>: Condition "compress", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1238: <b>cond_true</b>: Condition "compress", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1277: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (magic) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1280: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1282: <b>cond_false</b>: Condition "ret != 75UL /* sizeof (header) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1285: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1288: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1291: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1294: <b>check_return</b>: Calling function "lseek(fd, le64_to_cpu(header.rgd_offset) << 9, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/block/vmdk.c:1294: <b>unchecked_value</b>: No check of the return value of "lseek(fd, le64_to_cpu(header.rgd_offset) << 9, 0)". > ><a name='def337'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def337'>[#def337]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:280: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:285: <b>check_return</b>: Calling function "setsockopt(sock, 1, 2, &on, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-sockets.c:285: <b>unchecked_value</b>: No check of the return value of "setsockopt(sock, 1, 2, &on, 4U)". > ><a name='def338'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def338'>[#def338]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "host") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "port") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:126: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:131: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:132: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:133: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:134: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:137: <b>cond_true</b>: Condition "port_offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:139: <b>cond_true</b>: Condition "strlen(addr)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:140: <b>cond_false</b>: Condition "rc != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:145: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:148: <b>cond_true</b>: Condition "e != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:153: <b>cond_false</b>: Condition "slisten < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:160: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:162: <b>check_return</b>: Calling function "setsockopt(slisten, 1, 2, (void *)&on, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-sockets.c:162: <b>unchecked_value</b>: No check of the return value of "setsockopt(slisten, 1, 2, (void *)&on, 4U)". > ><a name='def339'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def339'>[#def339]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "host") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "port") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:126: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:131: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:132: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:133: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:134: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:137: <b>cond_true</b>: Condition "port_offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:139: <b>cond_true</b>: Condition "strlen(addr)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:140: <b>cond_false</b>: Condition "rc != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:145: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:148: <b>cond_true</b>: Condition "e != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:153: <b>cond_false</b>: Condition "slisten < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:160: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:164: <b>cond_true</b>: Condition "e->ai_family == 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:166: <b>check_return</b>: Calling function "setsockopt(slisten, 41, 26, (void *)&off, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-sockets.c:166: <b>unchecked_value</b>: No check of the return value of "setsockopt(slisten, 41, 26, (void *)&off, 4U)". > ><a name='def340'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def340'>[#def340]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:424: <b>cond_true</b>: Condition "addr == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:427: <b>cond_false</b>: Condition "port == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:427: <b>cond_false</b>: Condition "strlen(port) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:430: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:432: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:433: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:434: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:435: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:437: <b>cond_false</b>: Condition "0 != (rc = getaddrinfo(addr, port, &ai, &peer))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:441: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:451: <b>cond_true</b>: Condition "addr == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:454: <b>cond_true</b>: Condition "!port", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:457: <b>cond_false</b>: Condition "0 != (rc = getaddrinfo(addr, port, &ai, &local))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:461: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:465: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:469: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:470: <b>check_return</b>: Calling function "setsockopt(sock, 1, 2, (void *)&on, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qemu-sockets.c:470: <b>unchecked_value</b>: No check of the return value of "setsockopt(sock, 1, 2, (void *)&on, 4U)". > ><a name='def341'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def341'>[#def341]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:393: <b>switch</b>: Switch case value "225"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:394: <b>switch_case</b>: Reached case "225"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:395: <b>cond_false</b>: Condition "devep != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:396: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:398: <b>switch</b>: Switch case value "USB_MSDM_CBW"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:399: <b>switch_case</b>: Reached case "USB_MSDM_CBW"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:400: <b>cond_false</b>: Condition "p->iov.size != 31", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:403: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:405: <b>cond_false</b>: Condition "le32_to_cpu(cbw.sig) != 1128420181", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:409: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:411: <b>cond_false</b>: Condition "cbw.lun != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:414: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:417: <b>cond_true</b>: Condition "s->data_len == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:419: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:423: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:426: <b>cond_true</b>: Condition "le32_to_cpu(s->csw.residue) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>check_return</b>: Calling function "scsi_req_enqueue(SCSIRequest *)" without checking return value (as is done elsewhere 9 out of 11 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:133: <b>example_assign</b>: Assigning: "datalen" = return value from "scsi_req_enqueue(s->current_req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:135: <b>example_checked</b>: "datalen" has its value checked in "datalen != 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:773: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(s->current->req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:774: <b>example_checked</b>: "n" has its value checked in "n".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1123: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1124: <b>example_checked</b>: "len" has its value checked in "len > 0L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:624: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(req->sreq)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:629: <b>example_checked</b>: "n" has its value checked in "n".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:560: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req->req)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:561: <b>example_checked</b>: "len" has its value checked in "len".</span> >qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>unchecked_value</b>: No check of the return value of "scsi_req_enqueue(s->req)". > ><a name='def342'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def342'>[#def342]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:286: <b>cond_false</b>: Condition "pagetable_index >= s->max_table_entries", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:286: <b>cond_false</b>: Condition "s->pagetable[pagetable_index] == 4294967295U", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:287: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:297: <b>cond_true</b>: Condition "write", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:297: <b>cond_true</b>: Condition "s->last_bitmap_offset != bitmap_offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:302: <b>check_return</b>: Calling function "bdrv_pwrite_sync(BlockDriverState *, int64_t, void const *, int)" without checking return value (as is done elsewhere 23 out of 24 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/cow.c:122: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, offset, &bitmap, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/cow.c:123: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:382: <b>example_checked</b>: "bdrv_pwrite_sync(bs->file, l2_offset + l2_index * 8UL, &tmp, 8)" has its value checked in "bdrv_pwrite_sync(bs->file, l2_offset + l2_index * 8UL, &tmp, 8) < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-cluster.c:145: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, s->l1_table_offset + 8 * l1_start_index, buf, 512)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-cluster.c:147: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:265: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, s->refcount_table_offset + refcount_table_index * 8UL, &data64, 8)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:268: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:785: <b>example_checked</b>: "bdrv_pwrite_sync(extent->file, (int64_t)m_data->l2_offset * 512L + m_data->l2_index * 4UL, &m_data->offset, 4)" has its value checked in "bdrv_pwrite_sync(extent->file, (int64_t)m_data->l2_offset * 512L + m_data->l2_index * 4UL, &m_data->offset, 4) < 0".</span> >qemu-kvm-1.2.0/block/vpc.c:302: <b>unchecked_value</b>: No check of the return value of "bdrv_pwrite_sync(bs->file, bitmap_offset, bitmap, s->bitmap_size)". > ><a name='def343'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def343'>[#def343]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1274: <b>check_return</b>: Calling function "strstart(char const *, char const *, char const **)" without checking return value (as is done elsewhere 74 out of 76 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:95: <b>example_checked</b>: "strstart(file, "nbd:", &host_spec)" has its value checked in "strstart(file, "nbd:", &host_spec)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1055: <b>example_checked</b>: "strstart(filename, "/dev/fd", NULL)" has its value checked in "strstart(filename, "/dev/fd", NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:170: <b>example_checked</b>: "strstart(filename, "rbd:", &start)" has its value checked in "strstart(filename, "rbd:", &start)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1024: <b>example_checked</b>: "strstart(dirname, "fat:", NULL)" has its value checked in "strstart(dirname, "fat:", NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dump.c:847: <b>example_checked</b>: "strstart(file, "file:", &p)" has its value checked in "strstart(file, "file:", &p)".</span> >qemu-kvm-1.2.0/block/sheepdog.c:1274: <b>unchecked_value</b>: No check of the return value of "strstart(filename, "sheepdog:", &vdiname)". > ><a name='def344'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def344'>[#def344]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1094: <b>check_return</b>: Calling function "strstart(char const *, char const *, char const **)" without checking return value (as is done elsewhere 74 out of 76 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:95: <b>example_checked</b>: "strstart(file, "nbd:", &host_spec)" has its value checked in "strstart(file, "nbd:", &host_spec)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1055: <b>example_checked</b>: "strstart(filename, "/dev/fd", NULL)" has its value checked in "strstart(filename, "/dev/fd", NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:170: <b>example_checked</b>: "strstart(filename, "rbd:", &start)" has its value checked in "strstart(filename, "rbd:", &start)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1024: <b>example_checked</b>: "strstart(dirname, "fat:", NULL)" has its value checked in "strstart(dirname, "fat:", NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dump.c:847: <b>example_checked</b>: "strstart(file, "file:", &p)" has its value checked in "strstart(file, "file:", &p)".</span> >qemu-kvm-1.2.0/block/sheepdog.c:1094: <b>unchecked_value</b>: No check of the return value of "strstart(filename, "sheepdog:", (char const **)&filename)". > ><a name='def345'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def345'>[#def345]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:738: <b>cond_false</b>: Condition "!len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:740: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:743: <b>cond_true</b>: Condition "rc >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:745: <b>cond_true</b>: Condition "ret != len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:749: <b>check_return</b>: Calling function "socket_set_cork(csock, 0)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> >qemu-kvm-1.2.0/nbd.c:749: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(csock, 0)". > ><a name='def346'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def346'>[#def346]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:738: <b>cond_false</b>: Condition "!len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:740: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:741: <b>check_return</b>: Calling function "socket_set_cork(csock, 1)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> >qemu-kvm-1.2.0/nbd.c:741: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(csock, 1)". > ><a name='def347'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def347'>[#def347]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:147: <b>check_return</b>: Calling function "fcntl(fd, 4, f & 0xfffffffffffff7ff)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/oslib-posix.c:147: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, f & 0xfffffffffffff7ff)". > ><a name='def348'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def348'>[#def348]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:154: <b>check_return</b>: Calling function "fcntl(fd, 4, f | 0x800)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/oslib-posix.c:154: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, f | 0x800)". > ><a name='def349'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def349'>[#def349]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:161: <b>check_return</b>: Calling function "fcntl(fd, 2, f | 1)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/oslib-posix.c:161: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 2, f | 1)". > ><a name='def350'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def350'>[#def350]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:242: <b>check_return</b>: Calling function "stat(path, &st)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/oslib-posix.c:242: <b>unchecked_value</b>: No check of the return value of "stat(path, &st)". > ><a name='def351'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def351'>[#def351]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:106: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:121: <b>cond_true</b>: Condition "dinfo", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_true</b>: Condition "i < 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_true</b>: Condition "i < 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_false</b>: Condition "i < 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:134: <b>cond_true</b>: Condition "bios_name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:139: <b>cond_true</b>: Condition "bios_filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:140: <b>check_return</b>: Calling function "load_image_targphys(char const *, target_phys_addr_t, uint64_t)" without checking return value (as is done elsewhere 50 out of 60 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:73: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:77: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:400: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(info->kernel_filename, entry, info->ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:404: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:238: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(kernel_filename, 0UL, flash_size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:241: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:79: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(li->image_filename, 1073758208U, ram_size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:84: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:56: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:61: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> >qemu-kvm-1.2.0/hw/milkymist.c:140: <b>unchecked_value</b>: No check of the return value of "load_image_targphys(bios_filename, 8781824U, 524288UL)". > ><a name='def352'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def352'>[#def352]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:335: <b>cond_true</b>: Condition "(ret = so->s = qemu_socket(2, SOCK_STREAM, 0)) >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:343: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:343: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". > ><a name='def353'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def353'>[#def353]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:335: <b>cond_true</b>: Condition "(ret = so->s = qemu_socket(2, SOCK_STREAM, 0)) >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:341: <b>check_return</b>: Calling function "setsockopt(s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:341: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 2, (char *)&opt, 4U)". > ><a name='def354'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def354'>[#def354]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:431: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:431: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". > ><a name='def355'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def355'>[#def355]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:429: <b>check_return</b>: Calling function "setsockopt(s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:429: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 2, (char *)&opt, 4U)". > ><a name='def356'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def356'>[#def356]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:433: <b>check_return</b>: Calling function "setsockopt(s, 6, 1, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:433: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 6, 1, (char *)&opt, 4U)". > ><a name='def357'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def357'>[#def357]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:105: <b>cond_true</b>: Condition "spt->fd < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:109: <b>cond_false</b>: Condition "spt->fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:111: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:113: <b>cond_true</b>: Condition "len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:114: <b>check_return</b>: Calling function "lseek(spt->fd, block_nr * 512U, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/tftp.c:114: <b>unchecked_value</b>: No check of the return value of "lseek(spt->fd, block_nr * 512U, 0)". > ><a name='def358'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def358'>[#def358]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "channel != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "({...})", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:35: <b>cond_false</b>: Condition "client_fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:38: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>check_return</b>: Calling function "fcntl(client_fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>unchecked_value</b>: No check of the return value of "fcntl(client_fd, 4, 2048)". > ><a name='def359'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def359'>[#def359]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "115"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:349: <b>switch_case</b>: Reached case "115"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:351: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "110"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:352: <b>switch_case</b>: Reached case "110"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:356: <b>cond_false</b>: Condition "seen_cache", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:358: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:360: <b>cond_false</b>: Condition "bdrv_parse_cache_flags(optarg, &flags) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:362: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:363: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:365: <b>switch_case</b>: Reached case "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:366: <b>cond_false</b>: Condition "seen_aio", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:368: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:370: <b>cond_true</b>: Condition "!__coverity_strcmp(optarg, "native")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:372: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:376: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:377: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "115"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:349: <b>switch_case</b>: Reached case "115"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:351: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "98"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:379: <b>switch_case</b>: Reached case "98"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:381: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "112"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:382: <b>switch_case</b>: Reached case "112"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:384: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:387: <b>cond_false</b>: Condition "li < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:387: <b>cond_false</b>: Condition "li > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:389: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:391: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "111"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:392: <b>switch_case</b>: Reached case "111"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:394: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:396: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:397: <b>cond_false</b>: Condition "dev_offset < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:399: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:400: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "114"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:401: <b>switch_case</b>: Reached case "114"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:404: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "114"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:401: <b>switch_case</b>: Reached case "114"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:404: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:405: <b>switch_case</b>: Reached case "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:407: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:408: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:409: <b>cond_false</b>: Condition "partition < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:409: <b>cond_false</b>: Condition "partition > 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:410: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:411: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_false</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:452: <b>cond_false</b>: Condition "argc - optind != 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:458: <b>cond_false</b>: Condition "disconnect", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:470: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:472: <b>cond_false</b>: Condition "device", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:522: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:524: <b>cond_false</b>: Condition "device != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:527: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:534: <b>cond_false</b>: Condition "(ret = bdrv_open(bs, srcpath, flags, NULL)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:537: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:541: <b>cond_true</b>: Condition "partition != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:543: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:546: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:551: <b>cond_true</b>: Condition "sockpath", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:555: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:557: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:559: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:561: <b>cond_false</b>: Condition "device", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:569: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:580: <b>cond_false</b>: Condition "chdir("/") < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:582: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:585: <b>check_return</b>: Calling function "main_loop_wait(0)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:478:5: <b>cond_true</b>: Condition "nonblocking", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:480:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:482:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:496:5: <b>return_wrapper</b>: The function wraps and returns the value of "os_host_main_loop_wait(timeout)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:298:5: <b>cond_true</b>: Condition "timeout < 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:304:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:308:5: <b>return_wrapper</b>: The function wraps and returns the value of "select(nfds + 1, &rfds, &wfds, &xfds, tvarg)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:310:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:499:5: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> >qemu-kvm-1.2.0/qemu-nbd.c:585: <b>unchecked_value</b>: No check of the return value of "main_loop_wait(0)". > ><a name='def360'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def360'>[#def360]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:460: <b>cond_false</b>: Condition "qemu_rbd_parsename(filename, pool, 128 /* sizeof (pool) */, snap_buf, 128 /* sizeof (snap_buf) */, s->name, 96 /* sizeof (s->name) */, conf, 1024 /* sizeof (conf) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:465: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:469: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:472: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:475: <b>cond_true</b>: Condition "snap_buf[0] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:486: <b>cond_true</b>: Condition "flags & 0x20", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:488: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:496: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:498: <b>cond_false</b>: Condition "strstr(conf, "conf=") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:501: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:503: <b>cond_true</b>: Condition "conf[0] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:505: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:508: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:512: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:515: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:518: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:521: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:524: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:527: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:529: <b>cond_true</b>: Condition "s->snap != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:533: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:537: <b>check_return</b>: Calling function "fcntl(s->fds[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/block/rbd.c:537: <b>unchecked_value</b>: No check of the return value of "fcntl(s->fds[0], 4, 2048)". > ><a name='def361'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def361'>[#def361]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:460: <b>cond_false</b>: Condition "qemu_rbd_parsename(filename, pool, 128 /* sizeof (pool) */, snap_buf, 128 /* sizeof (snap_buf) */, s->name, 96 /* sizeof (s->name) */, conf, 1024 /* sizeof (conf) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:465: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:469: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:472: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:475: <b>cond_true</b>: Condition "snap_buf[0] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:486: <b>cond_true</b>: Condition "flags & 0x20", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:488: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:496: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:498: <b>cond_false</b>: Condition "strstr(conf, "conf=") == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:501: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:503: <b>cond_true</b>: Condition "conf[0] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:505: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:508: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:512: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:515: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:518: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:521: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:524: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:527: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:529: <b>cond_true</b>: Condition "s->snap != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:533: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:538: <b>check_return</b>: Calling function "fcntl(s->fds[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/block/rbd.c:538: <b>unchecked_value</b>: No check of the return value of "fcntl(s->fds[1], 4, 2048)". > ><a name='def362'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def362'>[#def362]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:209: <b>cond_false</b>: Condition "s->efd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:210: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:211: <b>check_return</b>: Calling function "fcntl(s->efd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/linux-aio.c:211: <b>unchecked_value</b>: No check of the return value of "fcntl(s->efd, 4, 2048)". > ><a name='def363'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def363'>[#def363]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1225y.c:56: <b>cond_true</b>: Condition "s->file", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1225y.c:57: <b>check_return</b>: Calling function "fseek(s->file, addr, 0)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/ds1225y.c:57: <b>unchecked_value</b>: No check of the return value of "fseek(s->file, addr, 0)". > ><a name='def364'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def364'>[#def364]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:176: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:184: <b>cond_false</b>: Condition "cpu == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:187: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:196: <b>cond_false</b>: Condition "ram_size > (268435456UL /* 0x100 << 20 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:201: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:214: <b>cond_true</b>: Condition "bios_name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:217: <b>cond_true</b>: Condition "filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:219: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:221: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:227: <b>cond_true</b>: Condition "bios_size > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:227: <b>cond_true</b>: Condition "bios_size <= 4194304 /* 4 * 1024 * 1024 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:234: <b>check_return</b>: Calling function "load_image_targphys(char const *, target_phys_addr_t, uint64_t)" without checking return value (as is done elsewhere 50 out of 60 times).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:73: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:77: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:400: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(info->kernel_filename, entry, info->ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:404: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:238: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(kernel_filename, 0UL, flash_size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:241: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:79: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(li->image_filename, 1073758208U, ram_size)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:84: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:56: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:61: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> >qemu-kvm-1.2.0/hw/mips_r4k.c:234: <b>unchecked_value</b>: No check of the return value of "load_image_targphys(filename, 532676608UL, 4194304UL)". > ><a name='def365'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def365'>[#def365]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:372: <b>cond_false</b>: Condition "bind(so->s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:375: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:378: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/udp.c:378: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". > ><a name='def366'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def366'>[#def366]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:372: <b>cond_false</b>: Condition "bind(so->s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:375: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:376: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/udp.c:376: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 2, (char *)&opt, 4U)". > ><a name='def367'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def367'>[#def367]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_true</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:306: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:306: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)". > ><a name='def368'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def368'>[#def368]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_true</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:309: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:314: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:316: <b>cond_true</b>: Condition "src.sin_addr.s_addr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_false</b>: Condition "so->so_state & 0x1000", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>cond_true</b>: Condition "so->so_tcpcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:301: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_false</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:309: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:316: <b>cond_false</b>: Condition "src.sin_addr.s_addr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_false</b>: Condition "so != &slirp->tcb", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:324: <b>cond_true</b>: Condition "so != &slirp->udb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:325: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:328: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:328: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)". > ><a name='def369'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def369'>[#def369]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:156: <b>check_return</b>: Calling function "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:156: <b>unchecked_value</b>: No check of the return value of "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". > ><a name='def370'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def370'>[#def370]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:201: <b>switch_default</b>: Reached default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_true</b>: Condition "so->s < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_false</b>: Condition "*__errno_location() == 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:217: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:217: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 10, (char *)&opt, 4U)". > ><a name='def371'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def371'>[#def371]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:201: <b>switch_default</b>: Reached default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_true</b>: Condition "so->s < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_false</b>: Condition "*__errno_location() == 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:215: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:215: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 2, (char *)&opt, 4U)". > ><a name='def372'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def372'>[#def372]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:267: <b>check_return</b>: Calling function "select(0, &fdset, &fdset, &fdset, &t)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/slirp/misc.c:267: <b>unchecked_value</b>: No check of the return value of "select(0, &fdset, &fdset, &fdset, &t)". > ><a name='def373'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def373'>[#def373]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>cond_true</b>: Condition "(fd = open("/dev/net/tun", 2)) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:44: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:47: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:51: <b>cond_true</b>: Condition "*vnet_hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:54: <b>cond_true</b>: Condition "ioctl(fd, 2147767503UL /* (((2U << 0 + 8 + 8 + 14) | (0x54 << 0 + 8)) | (0xcf << 0)) | (sizeof (unsigned int) << 0 + 8 + 8) */, &features) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:54: <b>cond_true</b>: Condition "features & 16384", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:58: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:60: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:62: <b>cond_true</b>: Condition "vnet_hdr_required", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:62: <b>cond_false</b>: Condition "!*vnet_hdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:67: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:70: <b>cond_true</b>: Condition "ifname[0] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:71: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:73: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:75: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:83: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:85: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/net/tap-linux.c:85: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". > ><a name='def374'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def374'>[#def374]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:80: <b>cond_false</b>: Condition "m->m_hdr.mh_len <= 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:83: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:90: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:93: <b>check_return</b>: Calling function "sosendoob(so)" without checking return value. It wraps a library function that may fail and return an error code.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298:2: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301:2: <b>cond_true</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:303:3: <b>return_wrapper</b>: The function wraps and returns the value of "slirp_send(so, sb->sb_rptr, so->so_urgc, 1)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_false</b>: Condition "so->extra", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831:2: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:833:2: <b>return_wrapper</b>: The function wraps and returns the value of "send(so->s, buf, len, flags)"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307:2: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:330:2: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:334:2: <b>cond_true</b>: Condition "sb->sb_rptr >= sb->sb_data + sb->sb_datalen", taking true branch</span> >qemu-kvm-1.2.0/slirp/sbuf.c:93: <b>unchecked_value</b>: No check of the return value of "sosendoob(so)". > ><a name='def375'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def375'>[#def375]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:70: <b>cond_false</b>: Condition "qemu_pipe(notifier_fds) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:73: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:75: <b>cond_false</b>: Condition "!p->pool", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:78: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:80: <b>cond_false</b>: Condition "!p->completed", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:87: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:91: <b>check_return</b>: Calling function "fcntl(p->rfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:91: <b>unchecked_value</b>: No check of the return value of "fcntl(p->rfd, 4, 2048)". > ><a name='def376'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def376'>[#def376]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:70: <b>cond_false</b>: Condition "qemu_pipe(notifier_fds) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:73: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:75: <b>cond_false</b>: Condition "!p->pool", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:78: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:80: <b>cond_false</b>: Condition "!p->completed", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:87: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:92: <b>check_return</b>: Calling function "fcntl(p->wfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:92: <b>unchecked_value</b>: No check of the return value of "fcntl(p->wfd, 4, 2048)". > ><a name='def377'/><b>Error: <span style='background: #C0FF00;'>CHROOT</span> (CWE-243):</b> <a href ='#def377'>[#def377]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "61"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5714: <b>switch_case</b>: Reached case "61"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5715: <b>cond_false</b>: Condition "!(p = lock_user_string(arg1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5716: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5717: <b>chroot_call</b>: Calling chroot: "chroot(p)".</span> >qemu-kvm-1.2.0/linux-user/syscall.c:5717: <b>chroot</b>: Calling function "get_errno(abi_long)" after chroot() but before calling chdir("/"). > ><a name='def378'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def378'>[#def378]</a> >qemu-kvm-1.2.0/target-arm/helper.c:565: <b>result_independent_of_operands</b>: (ret & (20 /* 0xa << 1 */)) >> 5 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def379'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def379'>[#def379]</a> >qemu-kvm-1.2.0/hw/megasas.c:1222: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def380'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def380'>[#def380]</a> >qemu-kvm-1.2.0/hw/megasas.c:910: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def381'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def381'>[#def381]</a> >qemu-kvm-1.2.0/qapi/opts-visitor.c:287: <b>result_independent_of_operands</b>: -9223372036854775808LL /* -9223372036854775807L - 1 */ <= val is always true regardless of the values of its operands. This occurs as the logical second operand of '&&'. > ><a name='def382'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def382'>[#def382]</a> >qemu-kvm-1.2.0/hw/megasas.c:1105: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def383'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def383'>[#def383]</a> >qemu-kvm-1.2.0/hw/megasas.c:954: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def384'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def384'>[#def384]</a> >qemu-kvm-1.2.0/hw/megasas.c:695: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def385'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def385'>[#def385]</a> >qemu-kvm-1.2.0/hw/pxa2xx_lcd.c:622: <b>result_independent_of_operands</b>: *((uint16_t *)src) & (16777216 /* 1 << 24 */) is always 0 regardless of the values of its operands. This occurs as the operand of assignment. > ><a name='def386'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def386'>[#def386]</a> >qemu-kvm-1.2.0/target-sh4/translate.c:1414: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. > ><a name='def387'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def387'>[#def387]</a> >qemu-kvm-1.2.0/target-sh4/translate.c:1418: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. > ><a name='def388'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def388'>[#def388]</a> >qemu-kvm-1.2.0/target-sh4/translate.c:1423: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. > ><a name='def389'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def389'>[#def389]</a> >qemu-kvm-1.2.0/target-sh4/translate.c:1430: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. > ><a name='def390'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def390'>[#def390]</a> >qemu-kvm-1.2.0/target-s390x/int_helper.c:60: <b>result_independent_of_operands</b>: (__uint128_t)env->regs[r1] << 64 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. > ><a name='def391'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def391'>[#def391]</a> >qemu-kvm-1.2.0/target-s390x/int_helper.c:40: <b>result_independent_of_operands</b>: res >> 64 is 0 regardless of the values of its operands. This occurs as the operand of assignment. > ><a name='def392'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def392'>[#def392]</a> >qemu-kvm-1.2.0/hw/imx_ccm.c:156: <b>result_independent_of_operands</b>: (s->ccmr & (6U /* 3 << 1 */)) == 1 is always false regardless of the values of its operands. This occurs as the logical operand of if. > ><a name='def393'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def393'>[#def393]</a> >qemu-kvm-1.2.0/hw/sun4c_intctl.c:129: <b>result_independent_of_operands</b>: s->reg & 0x80000000U is always 0 regardless of the values of its operands. This occurs as the logical operand of '!'. > ><a name='def394'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def394'>[#def394]</a> >qemu-kvm-1.2.0/hw/max111x.c:76: <b>missing_parentheses</b>: ((value & 4294967279U /* ~(1 << 4) */) >> 2 /* 2 + 0 */) & 4 is always 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. Did you intend to apply '&' to 2 /* 2 + 0 */ and 4? If so, parentheses would be required to force this interpretation. > ><a name='def395'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def395'>[#def395]</a> >qemu-kvm-1.2.0/hw/spapr_vscsi.c:574: <b>pointless_expression</b>: The expression cdb[1] & 1 || cdb[1] & 1 does not accomplish anything because it evaluates to either of its identical operands, cdb[1] & 1. Did you intend the operands to be different? > ><a name='def396'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def396'>[#def396]</a> >qemu-kvm-1.2.0/buffered_file.c:226: <b>result_independent_of_operands</b>: new_rate > 18446744073709551615UL is always false regardless of the values of its operands. This occurs as the logical operand of if. > ><a name='def397'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def397'>[#def397]</a> >qemu-kvm-1.2.0/sparc-dis.c:3053: <b>result_independent_of_operands</b>: (unsigned int)((insn >> 14) & 31) < 32 is always true regardless of the values of its operands. This occurs as the logical operand of if. > ><a name='def398'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def398'>[#def398]</a> >qemu-kvm-1.2.0/sparc-dis.c:3061: <b>result_independent_of_operands</b>: (unsigned int)((insn >> 25) & 31) < 32 is always true regardless of the values of its operands. This occurs as the logical operand of if. > ><a name='def399'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def399'>[#def399]</a> >/usr/include/bits/stdio2.h:287: <b>pointless_expression</b>: The expression 1 /* !0 */ || 1 /* !0 */ does not accomplish anything because it evaluates to either of its identical operands, 1 /* !0 */. Did you intend the operands to be different? > ><a name='def400'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def400'>[#def400]</a> >qemu-kvm-1.2.0/target-i386/arch_memory_mapping.c:134: <b>result_independent_of_operands</b>: (pde & 2088960) << 19 is 0 regardless of the values of its operands. This occurs as the bitwise second operand of '|'. > ><a name='def401'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def401'>[#def401]</a> >qemu-kvm-1.2.0/hw/qdev-addr.c:52: <b>result_independent_of_operands</b>: (uint64_t)value <= 18446744073709551615UL /* (uint64_t)~((target_phys_addr_t)0) */ is always true regardless of the values of its operands. This occurs as the logical operand of if. > ><a name='def402'/><b>Error: <span style='background: #C0FF00;'>COPY_PASTE_ERROR</span>:</b> <a href ='#def402'>[#def402]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/seg_helper.c:128: <b>original</b>: "lduw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + index + 2U) + guest_base))" looks like the original copy.</span> >qemu-kvm-1.2.0/target-i386/seg_helper.c:131: <b>copy_paste_error</b>: "lduw_le_p" in "lduw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + index + 4U) + guest_base))" looks like a copy-paste error. Should it say "ldl_le_p" instead? > ><a name='def403'/><b>Error: <span style='background: #C0FF00;'>COPY_PASTE_ERROR</span>:</b> <a href ='#def403'>[#def403]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/seg_helper.c:352: <b>original</b>: "stw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + (34 + i * 4)) + guest_base), env->segs[i].selector)" looks like the original copy.</span> >qemu-kvm-1.2.0/target-i386/seg_helper.c:336: <b>copy_paste_error</b>: "stw_le_p" in "stw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + (72 + i * 4)) + guest_base), env->segs[i].selector)" looks like a copy-paste error. Should it say "stl_le_p" instead? > ><a name='def404'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def404'>[#def404]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:122: <b>assignment</b>: Assigning: "head" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:128: <b>null</b>: At condition "head == NULL", the value of "head" must be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:128: <b>dead_error_condition</b>: The condition "head == NULL" must be true.</span> >qemu-kvm-1.2.0/migration.c:132: <b>dead_error_begin</b>: Execution cannot reach this statement "caps->next = g_malloc0(16UL);". > ><a name='def405'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def405'>[#def405]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2404: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2403: <b>equality_cond</b>: Jumping to case "6".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2407: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[6,6], [10,10]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2407: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2417: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def406'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def406'>[#def406]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2430: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2429: <b>equality_cond</b>: Jumping to case "7".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2433: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[7,7], [11,11]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2433: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2442: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def407'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def407'>[#def407]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2352: <b>equality_cond</b>: Jumping to case "4".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2353: <b>equality_cond</b>: Jumping to case "8".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2356: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [8,8]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2356: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2366: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def408'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def408'>[#def408]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2377: <b>equality_cond</b>: Jumping to case "5".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2378: <b>equality_cond</b>: Jumping to case "9".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2381: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[5,5], [9,9]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2381: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2391: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def409'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def409'>[#def409]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def410'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def410'>[#def410]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def411'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def411'>[#def411]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2035: <b>assignment</b>: Assigning: "rm" = "modrm & 7".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2152: <b>between</b>: When switching on "rm", the value of "rm" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2152: <b>dead_error_condition</b>: The switch value "rm" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:2178: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def412'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def412'>[#def412]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2208: <b>assignment</b>: Assigning: "mod" = "(modrm >> 6) & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>between</b>: When switching on "mod", the value of "mod" must be between 0 and 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2209: <b>cond_cannot_single</b>: Condition "mod == 3", taking false branch. Now the value of "mod" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>cannot_single</b>: When switching on "mod", the value of "mod" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>dead_error_condition</b>: The switch value "mod" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:2231: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def413'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def413'>[#def413]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2208: <b>assignment</b>: Assigning: "mod" = "(modrm >> 6) & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>between</b>: When switching on "mod", the value of "mod" must be between 0 and 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2209: <b>cond_cannot_single</b>: Condition "mod == 3", taking false branch. Now the value of "mod" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>cannot_single</b>: When switching on "mod", the value of "mod" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>dead_error_condition</b>: The switch value "mod" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:2246: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def414'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def414'>[#def414]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:11077: <b>dead_error_condition</b>: The switch value "(ctx->opcode >> 6) & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-mips/translate.c:11097: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def415'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def415'>[#def415]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:521: <b>assignment</b>: Assigning: "addr" &= "7U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:522: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:522: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/serial.c:523: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def416'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def416'>[#def416]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:374: <b>assignment</b>: Assigning: "addr" &= "7U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:376: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:376: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/serial.c:377: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def417'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def417'>[#def417]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1305: <b>dead_error_condition</b>: The switch value "(insn >> 25) & 0xfU" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-unicore32/translate.c:1431: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def418'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def418'>[#def418]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/fpu_helper.c:260: <b>dead_error_condition</b>: The switch value "(env->fpscr >> 0) & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-ppc/fpu_helper.c:273: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def419'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def419'>[#def419]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def420'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def420'>[#def420]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def421'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def421'>[#def421]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def422'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def422'>[#def422]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:557: <b>assignment</b>: Assigning: "nslots" = "31".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:565: <b>const</b>: At condition "nslots < 1", the value of "nslots" must be equal to 31.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:565: <b>dead_error_condition</b>: The condition "nslots < 1" cannot be true.</span> >qemu-kvm-1.2.0/hw/shpc.c:566: <b>dead_error_line</b>: Execution cannot reach this statement "return 0;". > ><a name='def423'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def423'>[#def423]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:557: <b>assignment</b>: Assigning: "nslots" = "31".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>const</b>: At condition "nslots > 31", the value of "nslots" must be equal to 31.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>dead_error_condition</b>: The condition "nslots > 31" cannot be true.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>const</b>: At condition "nslots + 1 > 32", the value of "nslots" must be equal to 31.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>dead_error_condition</b>: The condition "nslots + 1 > 32" cannot be true.</span> >qemu-kvm-1.2.0/hw/shpc.c:571: <b>dead_error_line</b>: Execution cannot reach this statement "return -22;". > ><a name='def424'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def424'>[#def424]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking false branch. Now the value of "xop" is between 20 and 23.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking false branch. Now the value of "xop" is between 4 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking true branch. Now the value of "xop" is between 8 and 19.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_const</b>: Condition "xop != 14U", taking false branch. Now the value of "xop" is equal to 14.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_const</b>: Condition "xop >= 32U", taking false branch. Now the value of "xop" is equal to 30.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4966: <b>intervals</b>: When switching on "xop", the value of "xop" must be in one of the following intervals: {[4,7], [14,14], [20,23], [30,30]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4966: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/translate.c:5056: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def425'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def425'>[#def425]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop >= 32U", taking true branch. Now the value of "xop" is between 32 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop < 36U", taking false branch. Now the value of "xop" is between 36 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5059: <b>cond_between</b>: Condition "xop < 40U", taking true branch. Now the value of "xop" is between 36 and 39.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>between</b>: When switching on "xop", the value of "xop" must be between 36 and 39.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_single</b>: Condition "xop == 60U", taking false branch. Now the value of "xop" cannot be equal to 60.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_set</b>: Condition "xop == 62U", taking false branch. Now the value of "xop" cannot be equal to any of {60, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 31U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 61U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4963: <b>cond_cannot_set</b>: Condition "xop == 14U", taking false branch. Now the value of "xop" cannot be equal to any of {14, 31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4963: <b>cond_cannot_set</b>: Condition "xop == 30U", taking false branch. Now the value of "xop" cannot be equal to any of {14, 30, 31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>cannot_set</b>: When switching on "xop", the value of "xop" cannot be equal to any of {14, 30, 31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/translate.c:5114: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def426'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def426'>[#def426]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop >= 32U", taking true branch. Now the value of "xop" is between 32 and 44.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop < 36U", taking true branch. Now the value of "xop" is between 32 and 35.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>between</b>: When switching on "xop", the value of "xop" must be between 32 and 35.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_single</b>: Condition "xop == 60U", taking false branch. Now the value of "xop" cannot be equal to 60.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_set</b>: Condition "xop == 62U", taking false branch. Now the value of "xop" cannot be equal to any of {60, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 31U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 61U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>cannot_set</b>: When switching on "xop", the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/translate.c:4960: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def427'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def427'>[#def427]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def428'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def428'>[#def428]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def429'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def429'>[#def429]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def430'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def430'>[#def430]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def431'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def431'>[#def431]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1356: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1356: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1357: <b>dead_error_begin</b>: Execution cannot reach this statement "len = strlen(k_platform) + ...". > ><a name='def432'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def432'>[#def432]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1382: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1382: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1383: <b>dead_error_line</b>: Execution cannot reach this statement "size += 2;". > ><a name='def433'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def433'>[#def433]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1420: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1420: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1421: <b>dead_error_begin</b>: Execution cannot reach this statement "do { > sp -= 4U; > ({ > a...". > ><a name='def434'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def434'>[#def434]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1439: <b>assignment</b>: Assigning: "stack_adjust" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1453: <b>const</b>: At condition "stack_adjust == 8", the value of "stack_adjust" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1453: <b>dead_error_condition</b>: The condition "stack_adjust == 8" cannot be true.</span> >qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1455: <b>dead_error_line</b>: Execution cannot reach this statement "tcg_out_pop(s, 1);". > ><a name='def435'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def435'>[#def435]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5110: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:5111: <b>dead_error_line</b>: Execution cannot reach this statement "goto badframe;". > ><a name='def436'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def436'>[#def436]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5114: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:5115: <b>dead_error_line</b>: Execution cannot reach this statement "goto badframe;". > ><a name='def437'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def437'>[#def437]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:482: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:482: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:482: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def438'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def438'>[#def438]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:487: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:487: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:487: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_MigrationStats(m...". > ><a name='def439'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def439'>[#def439]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:492: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:492: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:492: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_MigrationStats(m...". > ><a name='def440'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def440'>[#def440]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:497: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:497: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:497: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_XBZRLECacheStats...". > ><a name='def441'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def441'>[#def441]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:502: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:502: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:502: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def442'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def442'>[#def442]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:29: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:32: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:32: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:32: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def443'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def443'>[#def443]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1331: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1355: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1355: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1355: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_PciDeviceInfoLis...". > ><a name='def444'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def444'>[#def444]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1277: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1284: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1284: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1284: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def445'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def445'>[#def445]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1277: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1289: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1289: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1289: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def446'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def446'>[#def446]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1409: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1409: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1409: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def447'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def447'>[#def447]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1441: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1441: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1441: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def448'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def448'>[#def448]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1447: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1447: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1447: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_PciBridgeInfo(m,...". > ><a name='def449'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def449'>[#def449]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1096: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1096: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1096: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def450'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def450'>[#def450]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1101: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1101: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1101: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def451'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def451'>[#def451]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1106: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1106: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1106: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def452'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def452'>[#def452]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1111: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1111: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1111: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def453'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def453'>[#def453]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1116: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1116: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1116: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def454'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def454'>[#def454]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1122: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1122: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1122: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_SpiceChannelList...". > ><a name='def455'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def455'>[#def455]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:920: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:926: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:926: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:926: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def456'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def456'>[#def456]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:920: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:931: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:931: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:931: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def457'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def457'>[#def457]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1582: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1587: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1587: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1587: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def458'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def458'>[#def458]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1582: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1592: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1592: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1592: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_NewImageMode(m, ...". > ><a name='def459'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def459'>[#def459]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2737: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2741: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2741: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2741: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def460'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def460'>[#def460]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:678: <b>assignment</b>: Assigning: "fn" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:680: <b>const</b>: At condition "fn", the value of "fn" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:680: <b>dead_error_condition</b>: The condition "fn" cannot be true.</span> >qemu-kvm-1.2.0/hw/spapr_vscsi.c:682: <b>dead_error_line</b>: Execution cannot reach this statement ";". > ><a name='def461'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def461'>[#def461]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:538: <b>assignment</b>: Assigning: "value" &= "0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:541: <b>const</b>: At condition "value & 0x40UL", the value of "value" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:541: <b>dead_error_condition</b>: The condition "value & 0x40UL" cannot be true.</span> >qemu-kvm-1.2.0/hw/xilinx_axienet.c:542: <b>dead_error_begin</b>: Execution cannot reach this statement "miiclkdiv = value & 0x3fUL;". > ><a name='def462'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def462'>[#def462]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4921: <b>cond_const</b>: Condition "err", taking false branch. Now the value of "err" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4932: <b>assignment</b>: Assigning: "err" |= "({...})".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4936: <b>assignment</b>: Assigning: "err" |= "({...})".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4939: <b>const</b>: At condition "err", the value of "err" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4939: <b>dead_error_condition</b>: The condition "err" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:4940: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". > ><a name='def463'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def463'>[#def463]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4925: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:4926: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". > ><a name='def464'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def464'>[#def464]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5062: <b>cond_const</b>: Condition "err", taking false branch. Now the value of "err" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5073: <b>assignment</b>: Assigning: "err" |= "({...})".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5077: <b>assignment</b>: Assigning: "err" |= "({...})".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5079: <b>assignment</b>: Assigning: "err" |= "({...})".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5081: <b>const</b>: At condition "err", the value of "err" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5081: <b>dead_error_condition</b>: The condition "err" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:5082: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". > ><a name='def465'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def465'>[#def465]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5066: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/signal.c:5067: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". > ><a name='def466'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def466'>[#def466]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:260: <b>assignment</b>: Assigning: "addr" = "(addr >> 9) & 0xfUL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:261: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 15.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:261: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/cuda.c:316: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def467'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def467'>[#def467]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:332: <b>assignment</b>: Assigning: "addr" = "(addr >> 9) & 0xfUL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:335: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 15.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:335: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/cuda.c:400: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def468'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def468'>[#def468]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def469'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def469'>[#def469]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def470'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def470'>[#def470]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def471'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def471'>[#def471]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:166: <b>cond_at_least</b>: Condition "count < 64L", taking false branch. Now the value of "count" is at least 64.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>at_least</b>: At condition "count < 64L", the value of "count" must be at least 64.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:162: <b>cond_cannot_single</b>: Condition "count == 0L", taking false branch. Now the value of "count" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>cannot_single</b>: At condition "count < 64L", the value of "count" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>dead_error_condition</b>: The condition "count < 64L" cannot be true.</span> >qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>dead_error_line</b>: Execution cannot reach this expression "a0 >> (count & 0x3fL)" inside statement "z1 = ((count < 64L) ? a0 >>...". > ><a name='def472'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def472'>[#def472]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/helper.c:2030: <b>dead_error_condition</b>: The switch value "desc & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/helper.c:2059: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def473'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def473'>[#def473]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/helper.c:2139: <b>dead_error_condition</b>: The switch value "desc & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/helper.c:2153: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def474'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def474'>[#def474]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:944: <b>cond_null</b>: Condition "penv", taking false branch. Now the value of "penv" is NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:953: <b>null</b>: At condition "penv", the value of "penv" must be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:953: <b>dead_error_condition</b>: The condition "penv" cannot be true.</span> >qemu-kvm-1.2.0/cpus.c:954: <b>dead_error_begin</b>: Execution cannot reach this statement "penv->stop = 0U;". > ><a name='def475'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def475'>[#def475]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4375: <b>dead_error_condition</b>: The condition "flags & 0U" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/syscall.c:4376: <b>dead_error_line</b>: Execution cannot reach this statement "return -22;". > ><a name='def476'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def476'>[#def476]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def477'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def477'>[#def477]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def478'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def478'>[#def478]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def479'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def479'>[#def479]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4957: <b>assignment</b>: Assigning: "disp" = "0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5063: <b>cond_const</b>: Condition "disp", taking false branch. Now the value of "disp" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5063: <b>cond_at_least</b>: Condition "disp", taking true branch. Now the value of "disp" is at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5066: <b>at_least</b>: At condition "(bfd_signed_vma)disp >= 0L", the value of "disp" must be at least 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5066: <b>dead_error_condition</b>: The condition "(bfd_signed_vma)disp >= 0L" must be true.</span> >qemu-kvm-1.2.0/i386-dis.c:5071: <b>dead_error_line</b>: Execution cannot reach this statement "if (modrm.mod != 1){ > *obu...". > ><a name='def480'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def480'>[#def480]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4957: <b>assignment</b>: Assigning: "disp" = "0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5139: <b>cond_const</b>: Condition "disp", taking false branch. Now the value of "disp" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5139: <b>cond_at_least</b>: Condition "disp", taking true branch. Now the value of "disp" is at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5142: <b>at_least</b>: At condition "(bfd_signed_vma)disp >= 0L", the value of "disp" must be at least 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5142: <b>dead_error_condition</b>: The condition "(bfd_signed_vma)disp >= 0L" must be true.</span> >qemu-kvm-1.2.0/i386-dis.c:5147: <b>dead_error_line</b>: Execution cannot reach this statement "if (modrm.mod != 1){ > *obu...". > ><a name='def481'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def481'>[#def481]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc.c:826: <b>dead_error_condition</b>: The switch value "(env->spr[986] >> 24) & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/ppc.c:839: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def482'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def482'>[#def482]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc.c:916: <b>dead_error_condition</b>: The switch value "(env->spr[986] >> 30) & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/ppc.c:929: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def483'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def483'>[#def483]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:373: <b>cond_at_least</b>: Condition "(int64_t)r == 0L", taking false branch. Now the value of "r" is at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>at_least</b>: At condition "(int64_t)r < 0L", the value of "r" must be at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:373: <b>cond_cannot_single</b>: Condition "(int64_t)r == 0L", taking false branch. Now the value of "r" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>cannot_single</b>: At condition "(int64_t)r < 0L", the value of "r" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>dead_error_condition</b>: The condition "(int64_t)r < 0L" cannot be true.</span> >qemu-kvm-1.2.0/target-s390x/cc_helper.c:376: <b>dead_error_line</b>: Execution cannot reach this statement "return 1U;". > ><a name='def484'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def484'>[#def484]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6629: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6631: <b>equality_cond</b>: Jumping to case "0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6632: <b>equality_cond</b>: Jumping to case "1U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6633: <b>equality_cond</b>: Jumping to case "2U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6634: <b>equality_cond</b>: Jumping to case "3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6646: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6646: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:6651: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def485'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def485'>[#def485]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6629: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6630: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6630: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:6635: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def486'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def486'>[#def486]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6671: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6673: <b>equality_cond</b>: Jumping to case "0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6674: <b>equality_cond</b>: Jumping to case "1U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6675: <b>equality_cond</b>: Jumping to case "2U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6676: <b>equality_cond</b>: Jumping to case "3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6687: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6687: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:6692: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def487'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def487'>[#def487]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6671: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6672: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6672: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:6677: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def488'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def488'>[#def488]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6949: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 0xfU".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6980: <b>cond_const</b>: Condition "op1 != 13U", taking false branch. Now the value of "op1" is equal to 13.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6980: <b>cond_const</b>: Condition "op1 != 15U", taking false branch. Now the value of "op1" is equal to 15.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6987: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 15.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6987: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:7113: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def489'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def489'>[#def489]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7201: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_const</b>: Condition "op1", taking false branch. Now the value of "op1" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_between</b>: Condition "op1", taking true branch. Now the value of "op1" is between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7209: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7209: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:7222: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def490'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def490'>[#def490]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7201: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_const</b>: Condition "op1", taking false branch. Now the value of "op1" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_between</b>: Condition "op1", taking true branch. Now the value of "op1" is between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7227: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7227: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:7240: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def491'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def491'>[#def491]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7132: <b>assignment</b>: Assigning: "sh" = "(insn >> 5) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7133: <b>cond_between</b>: Condition "sh == 0U", taking false branch. Now the value of "sh" is between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>between</b>: When switching on "sh", the value of "sh" must be between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7133: <b>cond_cannot_single</b>: Condition "sh == 0U", taking false branch. Now the value of "sh" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>cannot_single</b>: When switching on "sh", the value of "sh" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>dead_error_condition</b>: The switch value "sh" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:7284: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def492'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def492'>[#def492]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:475: <b>assignment</b>: Assigning: "saddr" = "(addr >> serial->it_shift) & 1UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:478: <b>between</b>: When switching on "saddr", the value of "saddr" must be between 0 and 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:478: <b>dead_error_condition</b>: The switch value "saddr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/escc.c:563: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def493'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def493'>[#def493]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:577: <b>assignment</b>: Assigning: "saddr" = "(addr >> serial->it_shift) & 1UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:580: <b>between</b>: When switching on "saddr", the value of "saddr" must be between 0 and 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:580: <b>dead_error_condition</b>: The switch value "saddr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/escc.c:597: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def494'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def494'>[#def494]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3939: <b>assignment</b>: Assigning: "nregs" = "((insn >> 8) & 3U) + 1U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3941: <b>between</b>: When switching on "nregs", the value of "nregs" must be between 1 and 4.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3941: <b>dead_error_condition</b>: The switch value "nregs" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:3963: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def495'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def495'>[#def495]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3870: <b>assignment</b>: Assigning: "size" = "(insn >> 10) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3924: <b>equality_cond</b>: Jumping to case "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3978: <b>equality_cond</b>: Jumping to case "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3928: <b>equality_cond</b>: Jumping to case "1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3981: <b>equality_cond</b>: Jumping to case "1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3932: <b>equality_cond</b>: Jumping to case "2".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3984: <b>equality_cond</b>: Jumping to case "2".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3977: <b>between</b>: When switching on "size", the value of "size" must be between 0 and 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3977: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:3987: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def496'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def496'>[#def496]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3870: <b>assignment</b>: Assigning: "size" = "(insn >> 10) & 3U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>between</b>: When switching on "size", the value of "size" must be between 0 and 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3871: <b>cond_cannot_single</b>: Condition "size == 3", taking false branch. Now the value of "size" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>cannot_single</b>: When switching on "size", the value of "size" cannot be equal to 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:3936: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def497'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def497'>[#def497]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def498'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def498'>[#def498]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def499'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def499'>[#def499]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def500'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def500'>[#def500]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def501'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def501'>[#def501]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1590: <b>assignment</b>: Assigning: "addr" = "addr1 & 7U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1594: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1594: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1645: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def502'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def502'>[#def502]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1602: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1602: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1605: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_feature;". > ><a name='def503'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def503'>[#def503]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1610: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1610: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1613: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_nsector;". > ><a name='def504'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def504'>[#def504]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1618: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1618: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1621: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_sector;". > ><a name='def505'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def505'>[#def505]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1626: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1626: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1629: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_lcyl;". > ><a name='def506'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def506'>[#def506]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1634: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1634: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> >qemu-kvm-1.2.0/hw/ide/core.c:1637: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_hcyl;". > ><a name='def507'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def507'>[#def507]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:914: <b>assignment</b>: Assigning: "addr" &= "7U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:917: <b>cond_const</b>: Condition "addr != 7U", taking false branch. Now the value of "addr" is equal to 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:920: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:920: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/ide/core.c:966: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def508'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def508'>[#def508]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1168: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1168: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1168: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def509'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def509'>[#def509]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1173: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1173: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1173: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def510'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def510'>[#def510]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1178: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1178: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1178: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def511'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def511'>[#def511]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1183: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1183: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1183: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def512'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def512'>[#def512]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1188: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1188: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1188: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def513'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def513'>[#def513]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1193: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1193: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1193: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def514'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def514'>[#def514]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:699: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:705: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:705: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:705: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def515'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def515'>[#def515]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:768: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:768: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:768: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockDeviceInfo(...". > ><a name='def516'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def516'>[#def516]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:773: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:773: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:773: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def517'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def517'>[#def517]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:778: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:778: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:778: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockDeviceIoSta...". > ><a name='def518'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def518'>[#def518]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:869: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:872: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:872: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:872: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def519'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def519'>[#def519]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:869: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:878: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:878: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:878: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockStats(m, (o...". > ><a name='def520'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def520'>[#def520]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:641: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:641: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:641: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def521'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def521'>[#def521]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:646: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:646: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:646: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def522'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def522'>[#def522]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:651: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:651: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:651: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def523'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def523'>[#def523]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:656: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:656: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:656: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". > ><a name='def524'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def524'>[#def524]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:977: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:977: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:977: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def525'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def525'>[#def525]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:982: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:982: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:982: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def526'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def526'>[#def526]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:987: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:987: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:987: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def527'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def527'>[#def527]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:992: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:992: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:992: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def528'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def528'>[#def528]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:997: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:997: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:997: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_VncClientInfoLis...". > ><a name='def529'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def529'>[#def529]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1857: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1857: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1857: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def530'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def530'>[#def530]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1862: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1862: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1862: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def531'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def531'>[#def531]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1867: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1867: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1867: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def532'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def532'>[#def532]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1872: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1872: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1872: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def533'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def533'>[#def533]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1877: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1877: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1877: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint32(m, (obj ?...". > ><a name='def534'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def534'>[#def534]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2335: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2338: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2338: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2338: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def535'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def535'>[#def535]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2335: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2343: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2343: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2343: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def536'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def536'>[#def536]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2285: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2288: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2288: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2288: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_size(m, (obj ? &...". > ><a name='def537'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def537'>[#def537]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2285: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2293: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2293: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2293: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def538'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def538'>[#def538]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2158: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2158: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2158: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def539'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def539'>[#def539]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2163: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2163: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2163: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def540'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def540'>[#def540]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2168: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2168: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2168: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def541'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def541'>[#def541]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2173: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2173: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2173: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def542'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def542'>[#def542]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2178: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2178: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2178: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def543'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def543'>[#def543]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2183: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2183: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2183: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def544'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def544'>[#def544]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2068: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2068: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2068: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def545'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def545'>[#def545]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2073: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2073: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2073: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def546'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def546'>[#def546]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2078: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2078: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2078: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def547'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def547'>[#def547]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2083: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2083: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2083: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def548'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def548'>[#def548]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2088: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2088: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2088: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def549'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def549'>[#def549]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2093: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2093: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2093: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_size(m, (obj ? &...". > ><a name='def550'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def550'>[#def550]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2098: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2098: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2098: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def551'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def551'>[#def551]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2103: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2103: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2103: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def552'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def552'>[#def552]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2108: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2108: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2108: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def553'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def553'>[#def553]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2113: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2113: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2113: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def554'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def554'>[#def554]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1963: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1963: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1963: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def555'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def555'>[#def555]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1968: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1968: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1968: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def556'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def556'>[#def556]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1973: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1973: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1973: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def557'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def557'>[#def557]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1978: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1978: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1978: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def558'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def558'>[#def558]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1983: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1983: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1983: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def559'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def559'>[#def559]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1988: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1988: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1988: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def560'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def560'>[#def560]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1993: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1993: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1993: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def561'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def561'>[#def561]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1998: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1998: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:1998: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def562'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def562'>[#def562]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2003: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2003: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2003: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def563'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def563'>[#def563]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2008: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2008: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2008: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def564'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def564'>[#def564]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2013: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2013: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2013: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def565'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def565'>[#def565]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2018: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2018: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2018: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_StringList(m, (o...". > ><a name='def566'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def566'>[#def566]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2023: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2023: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2023: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_StringList(m, (o...". > ><a name='def567'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def567'>[#def567]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2228: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2228: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2228: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def568'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def568'>[#def568]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2233: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2233: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2233: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint16(m, (obj ?...". > ><a name='def569'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def569'>[#def569]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2238: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2238: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2238: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def570'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def570'>[#def570]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2243: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2243: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2243: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint16(m, (obj ?...". > ><a name='def571'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def571'>[#def571]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2508: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2508: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2508: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int32(m, (obj ? ...". > ><a name='def572'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def572'>[#def572]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2513: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2513: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2513: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def573'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def573'>[#def573]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2518: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2518: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2518: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def574'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def574'>[#def574]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2603: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2607: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2607: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2607: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def575'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def575'>[#def575]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2603: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2612: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2612: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qapi-visit.c:2612: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". > ><a name='def576'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def576'>[#def576]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1494: <b>assignment</b>: Assigning: "fpu_insn" = "(dc->ir >> 7) & 7U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1496: <b>between</b>: When switching on "fpu_insn", the value of "fpu_insn" must be between 0 and 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1496: <b>dead_error_condition</b>: The switch value "fpu_insn" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-microblaze/translate.c:1578: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def577'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def577'>[#def577]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:650: <b>assignment</b>: Assigning: "subcode" = "dc->imm & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:661: <b>cond_const</b>: Condition "subcode >= 1U", taking false branch. Now the value of "subcode" is equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:661: <b>cond_between</b>: Condition "subcode >= 1U", taking true branch. Now the value of "subcode" is between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:666: <b>between</b>: When switching on "subcode", the value of "subcode" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:666: <b>dead_error_condition</b>: The switch value "subcode" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-microblaze/translate.c:683: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def578'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def578'>[#def578]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3082: <b>equality_cond</b>: Jumping to case "14".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3083: <b>equality_cond</b>: Jumping to case "30".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3084: <b>equality_cond</b>: Jumping to case "31".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3089: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[14,14], [30,31]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3089: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3099: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def579'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def579'>[#def579]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3173: <b>equality_cond</b>: Jumping to case "148".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3174: <b>equality_cond</b>: Jumping to case "149".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3175: <b>equality_cond</b>: Jumping to case "150".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3178: <b>between</b>: When switching on "op", the value of "op" must be between 148 and 150.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3178: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3188: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def580'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def580'>[#def580]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3194: <b>equality_cond</b>: Jumping to case "152".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3195: <b>equality_cond</b>: Jumping to case "153".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3196: <b>equality_cond</b>: Jumping to case "154".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3200: <b>between</b>: When switching on "op", the value of "op" must be between 152 and 154.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3200: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3210: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def581'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def581'>[#def581]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3218: <b>equality_cond</b>: Jumping to case "164".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3219: <b>equality_cond</b>: Jumping to case "165".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3222: <b>between</b>: When switching on "op", the value of "op" must be between 164 and 165.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3222: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3229: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def582'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def582'>[#def582]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1522: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1523: <b>equality_cond</b>: Jumping to case "24".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1524: <b>equality_cond</b>: Jumping to case "26".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1521: <b>equality_cond</b>: Jumping to case "8".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1539: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[8,8], [10,10], [24,24], [26,26]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1539: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1548: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def583'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def583'>[#def583]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1556: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1557: <b>equality_cond</b>: Jumping to case "25".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1558: <b>equality_cond</b>: Jumping to case "27".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1555: <b>equality_cond</b>: Jumping to case "9".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1571: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[9,9], [11,11], [25,25], [27,27]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1571: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1580: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def584'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def584'>[#def584]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1760: <b>equality_cond</b>: Jumping to case "118".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1761: <b>equality_cond</b>: Jumping to case "119".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1764: <b>between</b>: When switching on "op", the value of "op" must be between 118 and 119.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1764: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1773: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def585'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def585'>[#def585]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1784: <b>equality_cond</b>: Jumping to case "128".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1785: <b>equality_cond</b>: Jumping to case "129".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1786: <b>equality_cond</b>: Jumping to case "130".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1789: <b>between</b>: When switching on "op", the value of "op" must be between 128 and 130.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1789: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1799: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def586'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def586'>[#def586]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1637: <b>equality_cond</b>: Jumping to case "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1643: <b>equality_cond</b>: Jumping to case "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1638: <b>equality_cond</b>: Jumping to case "33".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1644: <b>equality_cond</b>: Jumping to case "33".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1639: <b>equality_cond</b>: Jumping to case "48".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1647: <b>equality_cond</b>: Jumping to case "48".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1640: <b>equality_cond</b>: Jumping to case "49".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1650: <b>equality_cond</b>: Jumping to case "49".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1656: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[32,33], [48,49]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1656: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1665: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def587'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def587'>[#def587]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1637: <b>equality_cond</b>: Jumping to case "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1638: <b>equality_cond</b>: Jumping to case "33".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1639: <b>equality_cond</b>: Jumping to case "48".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1640: <b>equality_cond</b>: Jumping to case "49".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1642: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[32,33], [48,49]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1642: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1653: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def588'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def588'>[#def588]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1709: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1719: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1710: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1722: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1729: <b>between</b>: When switching on "op", the value of "op" must be between 90 and 91.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1729: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1736: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def589'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def589'>[#def589]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1709: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1710: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1718: <b>between</b>: When switching on "op", the value of "op" must be between 90 and 91.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1718: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:1725: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def590'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def590'>[#def590]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1978: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1979: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1976: <b>equality_cond</b>: Jumping to case "12".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1977: <b>equality_cond</b>: Jumping to case "13".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1980: <b>equality_cond</b>: Jumping to case "28".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1987: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[10,13], [28,28]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1987: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2012: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def591'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def591'>[#def591]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2049: <b>equality_cond</b>: Jumping to case "150".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2062: <b>equality_cond</b>: Jumping to case "150".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2045: <b>equality_cond</b>: Jumping to case "36".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2075: <b>equality_cond</b>: Jumping to case "36".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2048: <b>equality_cond</b>: Jumping to case "38".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2078: <b>equality_cond</b>: Jumping to case "38".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2044: <b>equality_cond</b>: Jumping to case "4".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2059: <b>equality_cond</b>: Jumping to case "4".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2058: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [36,36], [38,38], [150,150]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2058: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2084: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def592'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def592'>[#def592]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2021: <b>equality_cond</b>: Jumping to case "29".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2031: <b>const</b>: When switching on "op", the value of "op" must be equal to 29.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2031: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:2035: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def593'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def593'>[#def593]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def594'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def594'>[#def594]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def595'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def595'>[#def595]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def596'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def596'>[#def596]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:434: <b>cond_notnull</b>: Condition "bus", taking true branch. Now the value of "bus" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:455: <b>notnull</b>: At condition "bus", the value of "bus" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:455: <b>dead_error_condition</b>: The condition "!bus" cannot be true.</span> >qemu-kvm-1.2.0/hw/qdev-monitor.c:456: <b>dead_error_line</b>: Execution cannot reach this statement "bus = sysbus_get_default();". > ><a name='def597'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def597'>[#def597]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:524: <b>dead_error_condition</b>: The switch value "idx & 3" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:534: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def598'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def598'>[#def598]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:513: <b>assignment</b>: Assigning: "patches" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>const</b>: At condition "patches != 0", the value of "patches" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>dead_error_condition</b>: The condition "patches != 0" cannot be true.</span> >qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>dead_error_line</b>: Execution cannot reach this expression "patches != 2" inside statement "if (patches != 0 && patches...". > ><a name='def599'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def599'>[#def599]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:563: <b>dead_error_condition</b>: The switch value "idx & 3" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:573: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def600'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def600'>[#def600]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 37", taking false branch. Now the value of "op" is equal to 37.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 42", taking false branch. Now the value of "op" is equal to 42.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 47", taking false branch. Now the value of "op" is equal to 47.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3542: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[37,37], [42,42], [47,47]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3542: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/monitor.c:3543: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def601'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def601'>[#def601]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 124", taking false branch. Now the value of "op" is equal to 124.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 38", taking false branch. Now the value of "op" is equal to 38.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 94", taking false branch. Now the value of "op" is equal to 94.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3573: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[38,38], [94,94], [124,124]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3573: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/monitor.c:3574: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def602'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def602'>[#def602]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8385: <b>equality_cond</b>: Jumping to case "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8386: <b>equality_cond</b>: Jumping to case "1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8400: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8389: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8403: <b>equality_cond</b>: Jumping to case "12".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8404: <b>equality_cond</b>: Jumping to case "13".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8407: <b>equality_cond</b>: Jumping to case "14".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8387: <b>equality_cond</b>: Jumping to case "2".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8388: <b>equality_cond</b>: Jumping to case "3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8392: <b>equality_cond</b>: Jumping to case "4".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8393: <b>equality_cond</b>: Jumping to case "5".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8394: <b>equality_cond</b>: Jumping to case "6".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8395: <b>equality_cond</b>: Jumping to case "7".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8398: <b>equality_cond</b>: Jumping to case "8".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8399: <b>equality_cond</b>: Jumping to case "9".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8479: <b>between</b>: When switching on "aregs", the value of "aregs" must be between 0 and 14.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8479: <b>dead_error_condition</b>: The switch value "aregs" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-mips/translate.c:8505: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def603'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def603'>[#def603]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2740: <b>equality_cond</b>: Jumping to case "1342177280U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2772: <b>equality_cond</b>: Jumping to case "134217728U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2742: <b>equality_cond</b>: Jumping to case "1409286144U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2759: <b>equality_cond</b>: Jumping to case "1476395008U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2757: <b>equality_cond</b>: Jumping to case "1543503872U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2774: <b>equality_cond</b>: Jumping to case "1946157056U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2776: <b>equality_cond</b>: Jumping to case "1946157061U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2773: <b>equality_cond</b>: Jumping to case "201326592U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2775: <b>equality_cond</b>: Jumping to case "201326597U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2739: <b>equality_cond</b>: Jumping to case "268435456U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2782: <b>equality_cond</b>: Jumping to case "329U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2741: <b>equality_cond</b>: Jumping to case "335544320U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2783: <b>equality_cond</b>: Jumping to case "336U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2758: <b>equality_cond</b>: Jumping to case "402653184U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2756: <b>equality_cond</b>: Jumping to case "469762048U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2760: <b>equality_cond</b>: Jumping to case "67108864U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2751: <b>equality_cond</b>: Jumping to case "67174400U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2764: <b>equality_cond</b>: Jumping to case "67239936U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2755: <b>equality_cond</b>: Jumping to case "67305472U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2761: <b>equality_cond</b>: Jumping to case "68157440U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2762: <b>equality_cond</b>: Jumping to case "68157445U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2752: <b>equality_cond</b>: Jumping to case "68222976U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2753: <b>equality_cond</b>: Jumping to case "68222981U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2763: <b>equality_cond</b>: Jumping to case "68288512U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2754: <b>equality_cond</b>: Jumping to case "68354048U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2780: <b>equality_cond</b>: Jumping to case "8U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2781: <b>equality_cond</b>: Jumping to case "9U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2801: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[8,9], [329,329], [336,336], [67108864,67108864], [67174400,67174400], [67239936,67239936], [67305472,67305472], [68157440,68157440], [68157445,68157445], [68222976,68222976], [68222981,68222981], [68288512,68288512], [68354048,68354048], [134217728,134217728], [201326592,201326592], [201326597,201326597], [268435456,268435456], [335544320,335544320], [402653184,402653184], [469762048,469762048], [1342177280,1342177280], [1409286144,1409286144], [1476395008,1476395008], [1543503872,1543503872], [1946157056,1946157056], [1946157061,1946157061]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2801: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-mips/translate.c:2887: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def604'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def604'>[#def604]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2740: <b>equality_cond</b>: Jumping to case "1342177280U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2742: <b>equality_cond</b>: Jumping to case "1409286144U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2759: <b>equality_cond</b>: Jumping to case "1476395008U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2757: <b>equality_cond</b>: Jumping to case "1543503872U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2739: <b>equality_cond</b>: Jumping to case "268435456U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2741: <b>equality_cond</b>: Jumping to case "335544320U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2758: <b>equality_cond</b>: Jumping to case "402653184U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2756: <b>equality_cond</b>: Jumping to case "469762048U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2760: <b>equality_cond</b>: Jumping to case "67108864U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2751: <b>equality_cond</b>: Jumping to case "67174400U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2764: <b>equality_cond</b>: Jumping to case "67239936U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2755: <b>equality_cond</b>: Jumping to case "67305472U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2761: <b>equality_cond</b>: Jumping to case "68157440U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2762: <b>equality_cond</b>: Jumping to case "68157445U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2752: <b>equality_cond</b>: Jumping to case "68222976U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2753: <b>equality_cond</b>: Jumping to case "68222981U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2763: <b>equality_cond</b>: Jumping to case "68288512U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2754: <b>equality_cond</b>: Jumping to case "68354048U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2893: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[67108864,67108864], [67174400,67174400], [67239936,67239936], [67305472,67305472], [68157440,68157440], [68157445,68157445], [68222976,68222976], [68222981,68222981], [68288512,68288512], [68354048,68354048], [268435456,268435456], [335544320,335544320], [402653184,402653184], [469762048,469762048], [1342177280,1342177280], [1409286144,1409286144], [1476395008,1476395008], [1543503872,1543503872]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2893: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-mips/translate.c:2978: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def605'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def605'>[#def605]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3609: <b>equality_cond</b>: Jumping to case "298".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3608: <b>equality_cond</b>: Jumping to case "42".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3622: <b>intervals</b>: When switching on "b >> 8", the value of "b" must be in one of the following intervals: {[42,42], [298,298]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3622: <b>dead_error_condition</b>: The switch value "b >> 8" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-i386/translate.c:3626: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def606'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def606'>[#def606]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3337: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3336: <b>equality_cond</b>: Jumping to case "8".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3343: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[8,8], [10,10]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3343: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3350: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def607'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def607'>[#def607]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3358: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3360: <b>equality_cond</b>: Jumping to case "25".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3369: <b>equality_cond</b>: Jumping to case "25".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3359: <b>equality_cond</b>: Jumping to case "27".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3363: <b>equality_cond</b>: Jumping to case "27".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3357: <b>equality_cond</b>: Jumping to case "9".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3382: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[9,9], [11,11], [25,25], [27,27]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3382: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3391: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def608'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def608'>[#def608]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3521: <b>equality_cond</b>: Jumping to case "128".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3522: <b>equality_cond</b>: Jumping to case "129".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3523: <b>equality_cond</b>: Jumping to case "130".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3526: <b>between</b>: When switching on "op", the value of "op" must be between 128 and 130.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3526: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3536: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def609'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def609'>[#def609]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3718: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3719: <b>equality_cond</b>: Jumping to case "13".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3717: <b>equality_cond</b>: Jumping to case "7".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3721: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[7,7], [11,11], [13,13]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3721: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3731: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def610'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def610'>[#def610]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3780: <b>equality_cond</b>: Jumping to case "10".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3779: <b>equality_cond</b>: Jumping to case "4".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3784: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [10,10]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3784: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3793: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def611'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def611'>[#def611]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3802: <b>equality_cond</b>: Jumping to case "11".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3801: <b>equality_cond</b>: Jumping to case "5".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3806: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[5,5], [11,11]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3806: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:3815: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def612'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def612'>[#def612]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def613'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def613'>[#def613]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def614'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def614'>[#def614]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6578: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6593: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6608: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6623: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6976: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6992: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7008: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7024: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6561: <b>assignment</b>: Assigning: "optype" = "OTHEROP".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7746: <b>intervals</b>: When switching on "optype", the value of "optype" must be in one of the following intervals: {[0,0], [2,2]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7750: <b>dead_error_condition</b>: The switch value "optype" cannot be "CMPOP".</span> >qemu-kvm-1.2.0/target-mips/translate.c:7750: <b>dead_error_begin</b>: Execution cannot reach this statement "case CMPOP:". > ><a name='def615'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def615'>[#def615]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:587: <b>dead_error_condition</b>: The switch value "(insn >> 3) & 7" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-m68k/translate.c:677: <b>dead_error_line</b>: Execution cannot reach this statement "return NULL_QREG;". > ><a name='def616'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def616'>[#def616]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1142: <b>assignment</b>: Assigning: "op" = "(insn >> 6) & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>between</b>: When switching on "op", the value of "op" must be between 1 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1151: <b>cond_cannot_single</b>: Condition "op", taking true branch. Now the value of "op" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>cannot_single</b>: When switching on "op", the value of "op" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-m68k/translate.c:1183: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def617'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def617'>[#def617]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:510: <b>dead_error_condition</b>: The switch value "(insn >> 3) & 7" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-m68k/translate.c:554: <b>dead_error_line</b>: Execution cannot reach this statement "return NULL_QREG;". > ><a name='def618'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def618'>[#def618]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def619'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def619'>[#def619]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def620'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def620'>[#def620]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def621'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def621'>[#def621]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def622'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def622'>[#def622]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def623'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def623'>[#def623]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def624'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def624'>[#def624]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:791: <b>assignment</b>: Assigning: "memory_map_mode" = "(s->gr[6] >> 2) & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:793: <b>between</b>: When switching on "memory_map_mode", the value of "memory_map_mode" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:793: <b>dead_error_condition</b>: The switch value "memory_map_mode" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/vga.c:806: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def625'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def625'>[#def625]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:851: <b>assignment</b>: Assigning: "memory_map_mode" = "(s->gr[6] >> 2) & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:853: <b>between</b>: When switching on "memory_map_mode", the value of "memory_map_mode" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:853: <b>dead_error_condition</b>: The switch value "memory_map_mode" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/vga.c:866: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def626'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def626'>[#def626]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:901: <b>assignment</b>: Assigning: "write_mode" = "s->gr[5] & 3".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:902: <b>between</b>: When switching on "write_mode", the value of "write_mode" must be between 0 and 3.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:902: <b>dead_error_condition</b>: The switch value "write_mode" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/vga.c:903: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def627'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def627'>[#def627]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def628'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def628'>[#def628]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def629'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def629'>[#def629]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8733: <b>equality_cond</b>: Jumping to case "251".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8736: <b>equality_cond</b>: Jumping to case "315".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8753: <b>intervals</b>: When switching on "num", the value of "num" must be in one of the following intervals: {[251,251], [315,315]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8753: <b>dead_error_condition</b>: The switch value "num" cannot reach the default case.</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8782: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def630'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def630'>[#def630]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:613: <b>assignment</b>: Assigning: "cert_count" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:616: <b>incr</b>: Incrementing "cert_count". The value of "cert_count" is now 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:616: <b>incr</b>: Incrementing "cert_count". The value of "cert_count" is now 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:619: <b>at_least</b>: At condition "cert_count == 0", the value of "cert_count" must be at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:619: <b>dead_error_condition</b>: The condition "cert_count == 0" cannot be true.</span> >qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:620: <b>dead_error_begin</b>: Execution cannot reach this statement "PK11_DestroyGenericObjects(...". > ><a name='def631'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def631'>[#def631]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:452: <b>dead_error_condition</b>: The switch value "(tlb->tte >> 61) & 3ULL" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/mmu_helper.c:453: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def632'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def632'>[#def632]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4563: <b>equality_cond</b>: Jumping to case "136".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4564: <b>equality_cond</b>: Jumping to case "137".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4565: <b>equality_cond</b>: Jumping to case "138".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4573: <b>between</b>: When switching on "opc", the value of "opc" must be between 136 and 138.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4573: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4584: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def633'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def633'>[#def633]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4666: <b>equality_cond</b>: Jumping to case "148".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4667: <b>equality_cond</b>: Jumping to case "150".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4668: <b>equality_cond</b>: Jumping to case "151".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4673: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[148,148], [150,151]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4673: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4683: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def634'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def634'>[#def634]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4967: <b>equality_cond</b>: Jumping to case "192".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4968: <b>equality_cond</b>: Jumping to case "194".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4973: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[192,192], [194,194]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4973: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4980: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def635'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def635'>[#def635]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4984: <b>equality_cond</b>: Jumping to case "210".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4985: <b>equality_cond</b>: Jumping to case "212".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4986: <b>equality_cond</b>: Jumping to case "213".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4987: <b>equality_cond</b>: Jumping to case "214".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4988: <b>equality_cond</b>: Jumping to case "215".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4989: <b>equality_cond</b>: Jumping to case "220".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4990: <b>equality_cond</b>: Jumping to case "243".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4999: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[210,210], [212,215], [220,220], [243,243]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4999: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:5030: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def636'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def636'>[#def636]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4238: <b>equality_cond</b>: Jumping to case "74".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4239: <b>equality_cond</b>: Jumping to case "75".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4240: <b>equality_cond</b>: Jumping to case "76".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4250: <b>between</b>: When switching on "opc", the value of "opc" must be between 74 and 76.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4250: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4262: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def637'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def637'>[#def637]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4361: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4373: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4362: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4377: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4363: <b>equality_cond</b>: Jumping to case "94".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4374: <b>equality_cond</b>: Jumping to case "94".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4364: <b>equality_cond</b>: Jumping to case "95".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4378: <b>equality_cond</b>: Jumping to case "95".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4385: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[90,91], [94,95]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4385: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4398: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def638'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def638'>[#def638]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4361: <b>equality_cond</b>: Jumping to case "90".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4362: <b>equality_cond</b>: Jumping to case "91".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4363: <b>equality_cond</b>: Jumping to case "94".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4364: <b>equality_cond</b>: Jumping to case "95".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4372: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[90,91], [94,95]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4372: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-s390x/translate.c:4381: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def639'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def639'>[#def639]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def640'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def640'>[#def640]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def641'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def641'>[#def641]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". > ><a name='def642'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def642'>[#def642]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def643'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def643'>[#def643]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def644'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def644'>[#def644]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:165: <b>assignment</b>: Assigning: "op" = "(insn >> 7) & 0xfU".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:170: <b>between</b>: When switching on "op", the value of "op" must be between 0 and 15.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:170: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/milkymist-pfpu.c:304: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def645'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def645'>[#def645]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/cmd646.c:135: <b>dead_error_condition</b>: The switch value "addr & 3UL" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/ide/cmd646.c:152: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def646'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def646'>[#def646]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7977: <b>dead_error_condition</b>: The switch value "(insn >> 25) & 0xfU" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-arm/translate.c:8969: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def647'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def647'>[#def647]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def648'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def648'>[#def648]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:288: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". > ><a name='def649'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def649'>[#def649]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:288: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>dead_error_condition</b>: The condition "obj" must be true.</span> >qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_GuestIpAddressLi...". > ><a name='def650'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def650'>[#def650]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def651'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def651'>[#def651]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> >qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". > ><a name='def652'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def652'>[#def652]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp-pci.c:108: <b>dead_error_condition</b>: The switch value "val & 3U" cannot reach the default case.</span> >qemu-kvm-1.2.0/hw/esp-pci.c:121: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def653'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def653'>[#def653]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:3874: <b>assignment</b>: Assigning: "is_data" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:4012: <b>const</b>: At condition "is_data", the value of "is_data" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:4012: <b>dead_error_condition</b>: The condition "is_data" cannot be true.</span> >qemu-kvm-1.2.0/arm-dis.c:4014: <b>dead_error_begin</b>: Execution cannot reach this statement "int i;". > ><a name='def654'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def654'>[#def654]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2320: <b>assignment</b>: Assigning: "length" = "((given >> 8) & 3L) + 1L".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2324: <b>cond_const</b>: Condition "length > 1", taking false branch. Now the value of "length" is equal to 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2324: <b>cond_between</b>: Condition "length > 1", taking true branch. Now the value of "length" is between 2 and 4.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2327: <b>between</b>: When switching on "length", the value of "length" must be between 1 and 4.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2327: <b>dead_error_condition</b>: The switch value "length" cannot reach the default case.</span> >qemu-kvm-1.2.0/arm-dis.c:2367: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def655'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def655'>[#def655]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2466: <b>assignment</b>: Assigning: "size" = "16".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2460: <b>assignment</b>: Assigning: "size" = "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2473: <b>assignment</b>: Assigning: "size" = "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2511: <b>assignment</b>: Assigning: "size" = "32".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2493: <b>assignment</b>: Assigning: "size" = "64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2499: <b>assignment</b>: Assigning: "size" = "8".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2520: <b>intervals</b>: When switching on "size", the value of "size" must be in one of the following intervals: {[8,8], [16,16], [32,32], [64,64]}.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2520: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> >qemu-kvm-1.2.0/arm-dis.c:2558: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". > ><a name='def656'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def656'>[#def656]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:145: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "4".</span> >qemu-kvm-1.2.0/hw/mcf_uart.c:145: <b>dead_error_begin</b>: Execution cannot reach this statement "case 4:". > ><a name='def657'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def657'>[#def657]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:147: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "5".</span> >qemu-kvm-1.2.0/hw/mcf_uart.c:147: <b>dead_error_begin</b>: Execution cannot reach this statement "case 5:". > ><a name='def658'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def658'>[#def658]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:150: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "6".</span> >qemu-kvm-1.2.0/hw/mcf_uart.c:150: <b>dead_error_line</b>: Execution cannot reach this statement "case 6:". > ><a name='def659'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def659'>[#def659]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:151: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "7".</span> >qemu-kvm-1.2.0/hw/mcf_uart.c:151: <b>dead_error_begin</b>: Execution cannot reach this statement "case 7:". > ><a name='def660'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def660'>[#def660]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:387: <b>assignment</b>: Assigning: "lma" = "false".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:394: <b>const</b>: At condition "lma", the value of "lma" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:394: <b>dead_error_condition</b>: The condition "lma" cannot be true.</span> >qemu-kvm-1.2.0/target-i386/arch_dump.c:395: <b>dead_error_line</b>: Execution cannot reach this statement "info->d_machine = 62;". > ><a name='def661'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def661'>[#def661]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:387: <b>assignment</b>: Assigning: "lma" = "false".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:401: <b>const</b>: At condition "lma", the value of "lma" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:401: <b>dead_error_condition</b>: The condition "lma" cannot be true.</span> >qemu-kvm-1.2.0/target-i386/arch_dump.c:402: <b>dead_error_line</b>: Execution cannot reach this statement "info->d_class = 2;". > ><a name='def662'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def662'>[#def662]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/sparc-dis.c:3053: <b>dead_error_condition</b>: The condition "(unsigned int)((insn >> 14) & 0x1fUL) < 32U" must be true.</span> >qemu-kvm-1.2.0/sparc-dis.c:3057: <b>dead_error_line</b>: Execution cannot reach this statement "(*info->fprintf_func)(strea...". > ><a name='def663'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def663'>[#def663]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/sparc-dis.c:3061: <b>dead_error_condition</b>: The condition "(unsigned int)((insn >> 25) & 0x1fUL) < 32U" must be true.</span> >qemu-kvm-1.2.0/sparc-dis.c:3065: <b>dead_error_line</b>: Execution cannot reach this statement "(*info->fprintf_func)(strea...". > ><a name='def664'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def664'>[#def664]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/arm-semi.c:226: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> >qemu-kvm-1.2.0/target-arm/arm-semi.c:228: <b>dead_error_line</b>: Execution cannot reach this statement "return 4294967295U;". > ><a name='def665'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def665'>[#def665]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:178: <b>assignment</b>: Assigning: "nextchr" = "-1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:215: <b>assignment</b>: Assigning: "nextchr" = "-1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>const</b>: At condition "nextchr == -1", the value of "nextchr" must be equal to -1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>dead_error_condition</b>: The condition "nextchr == -1" must be true.</span> >qemu-kvm-1.2.0/ui/curses.c:184: <b>dead_error_begin</b>: Execution cannot reach this statement "chr = nextchr;". > ><a name='def666'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def666'>[#def666]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:120: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> >qemu-kvm-1.2.0/hw/ppce500_pci.c:120: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". > ><a name='def667'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def667'>[#def667]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:142: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> >qemu-kvm-1.2.0/hw/ppce500_pci.c:142: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". > ><a name='def668'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def668'>[#def668]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:191: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> >qemu-kvm-1.2.0/hw/ppce500_pci.c:191: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". > ><a name='def669'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def669'>[#def669]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:213: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> >qemu-kvm-1.2.0/hw/ppce500_pci.c:213: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". > ><a name='def670'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def670'>[#def670]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:73: <b>cond_at_most</b>: Condition "data < 8", taking true branch. Now the value of "data" is at most 7.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:83: <b>equality_cond</b>: Jumping to case "2".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:84: <b>const</b>: At condition "data & 0x40", the value of "data" must be equal to 2.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:84: <b>dead_error_condition</b>: The condition "data & 0x40" cannot be true.</span> >qemu-kvm-1.2.0/hw/ds1338.c:85: <b>dead_error_line</b>: Execution cannot reach this statement "if (data & 0x20){ > data = ...". > ><a name='def671'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def671'>[#def671]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:253: <b>cond_notnull</b>: Condition "reader != NULL", taking true branch. Now the value of "reader" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>notnull</b>: At condition "reader", the value of "reader" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>dead_error_condition</b>: The condition "reader" must be true.</span> >qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>dead_error_line</b>: Execution cannot reach this expression ""invalid reader"" inside statement "printf("insert %s, returned...". > ><a name='def672'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def672'>[#def672]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:266: <b>cond_notnull</b>: Condition "reader != NULL", taking true branch. Now the value of "reader" is not NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>notnull</b>: At condition "reader", the value of "reader" cannot be NULL.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>dead_error_condition</b>: The condition "reader" must be true.</span> >qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>dead_error_line</b>: Execution cannot reach this expression ""invalid reader"" inside statement "printf("remove %s, returned...". > ><a name='def673'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def673'>[#def673]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:740: <b>cond_const</b>: Condition "bits != 256", taking false branch. Now the value of "bits" is equal to 256.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:798: <b>const</b>: At condition "bits == 256", the value of "bits" must be equal to 256.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:798: <b>dead_error_condition</b>: The condition "bits == 256" must be true.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:799: <b>dead_error_condition</b>: The condition "1" must be true.</span> >qemu-kvm-1.2.0/aes.c:826: <b>dead_error_line</b>: Execution cannot reach this statement "return 0;". > ><a name='def674'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def674'>[#def674]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_at_least</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:195: <b>cond_at_least</b>: Condition "quot > 65535U", taking true branch. Now the value of "quot" is at least 65536.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_at_least</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is at least 65536.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:195: <b>cond_at_most</b>: Condition "quot > 65535U", taking false branch. Now the value of "quot" is at most 65535.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_between</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is between 1 and 65535.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>at_least</b>: At condition "(int32_t)quot < 0", the value of "quot" must be at least 1.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_cannot_single</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>cannot_single</b>: At condition "(int32_t)quot < 0", the value of "quot" cannot be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>dead_error_condition</b>: The condition "(int32_t)quot < 0" cannot be true.</span> >qemu-kvm-1.2.0/target-m68k/op_helper.c:200: <b>dead_error_line</b>: Execution cannot reach this statement "flags |= 8U;". > ><a name='def675'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def675'>[#def675]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:616: <b>assignment</b>: Assigning: "persistent" = "0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:626: <b>const</b>: At condition "persistent", the value of "persistent" must be equal to 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:626: <b>dead_error_condition</b>: The condition "persistent" cannot be true.</span> >qemu-kvm-1.2.0/linux-user/flatload.c:627: <b>dead_error_line</b>: Execution cannot reach this statement "continue;". > ><a name='def676'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def676'>[#def676]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:741: <b>dead_error_condition</b>: The switch value "(env->dtlb[i].tte >> 61) & 3ULL" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/mmu_helper.c:742: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def677'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def677'>[#def677]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:778: <b>dead_error_condition</b>: The switch value "(env->itlb[i].tte >> 61) & 3ULL" cannot reach the default case.</span> >qemu-kvm-1.2.0/target-sparc/mmu_helper.c:779: <b>dead_error_line</b>: Execution cannot reach this statement "default:". > ><a name='def678'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def678'>[#def678]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:626: <b>assign_zero</b>: Assigning: "ioeventfds" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>cond_true</b>: Condition "fr < as->current_map.ranges + as->current_map.nr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>cond_true</b>: Condition "i < fr->mr->ioeventfd_nb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:635: <b>cond_false</b>: Condition "addrrange_intersects(fr->addr, tmp)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:641: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>cond_false</b>: Condition "i < fr->mr->ioeventfd_nb", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:642: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:643: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>cond_false</b>: Condition "fr < as->current_map.ranges + as->current_map.nr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:643: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:645: <b>var_deref_model</b>: Passing null pointer "ioeventfds" to function "address_space_add_del_ioeventfds(AddressSpace *, MemoryRegionIoeventfd *, unsigned int, MemoryRegionIoeventfd *, unsigned int)", which dereferences it.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:588:5: <b>cond_true</b>: Condition "iold < fds_old_nb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:589:9: <b>cond_true</b>: Condition "iold < fds_old_nb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:589:9: <b>cond_false</b>: Condition "inew == fds_new_nb", taking false branch</span> >qemu-kvm-1.2.0/memory.c:589:9: <b>deref_parm</b>: Directly dereferencing parameter "fds_new". > ><a name='def679'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def679'>[#def679]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:285: <b>cond_false</b>: Condition "req->dev", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:287: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:285: <b>var_compare_op</b>: Comparing "req->dev" to null implies that "req->dev" might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:287: <b>cond_true</b>: Condition "req->bus->unit_attention.key == 6", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:288: <b>var_deref_model</b>: Passing "req" to function "scsi_req_build_sense(SCSIRequest *, SCSISense)", which dereferences null "req->dev".</span> >qemu-kvm-1.2.0/hw/scsi-bus.c:664:5: <b>deref_parm</b>: Directly dereferencing parameter "req->dev". > ><a name='def680'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def680'>[#def680]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:464: <b>assign_zero</b>: Assigning: "buf" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:465: <b>cond_true</b>: Condition "virtqueue_pop(vq, &elem)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:473: <b>cond_false</b>: Condition "cur_len > len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:478: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/virtio-serial-bus.c:479: <b>var_deref_model</b>: Passing null pointer "buf" to function "iov_to_buf(struct iovec const *, unsigned int const, size_t, void *, size_t)", which dereferences it. ><span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:53:5: <b>cond_true</b>: Condition "offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:53:5: <b>cond_true</b>: Condition "i < iov_cnt", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:54:9: <b>cond_true</b>: Condition "offset < (iov + i).iov_len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:56:13: <b>deref_parm_field_in_call</b>: Function "memcpy(void * restrict, void const * restrict, size_t)" dereferences an offset off "buf".</span> > ><a name='def681'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def681'>[#def681]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:420: <b>assign_zero</b>: Assigning: "refcount_block" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:428: <b>cond_false</b>: Condition "length < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:430: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:430: <b>cond_false</b>: Condition "length == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:432: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:434: <b>cond_true</b>: Condition "addend < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:441: <b>cond_true</b>: Condition "cluster_offset <= last", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:450: <b>cond_false</b>: Condition "table_index != old_table_index", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:463: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block/qcow2-refcount.c:472: <b>var_deref_op</b>: Dereferencing null pointer "refcount_block". > ><a name='def682'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def682'>[#def682]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1047: <b>cond_true</b>: Condition "l1_size2 == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1048: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1049: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1056: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1059: <b>cond_true</b>: Condition "i < l1_size", taking true branch</span> >qemu-kvm-1.2.0/block/qcow2-refcount.c:1060: <b>var_deref_op</b>: Dereferencing null pointer "l1_table". > ><a name='def683'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def683'>[#def683]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1009"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2259: <b>switch_case</b>: Reached case "1009"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2260: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_advqueue(EHCIQueue *)", which dereferences it.</span> >qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:1963:5: <b>deref_parm</b>: Directly dereferencing parameter "q". > ><a name='def684'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def684'>[#def684]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1011"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2271: <b>switch_case</b>: Reached case "1011"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2272: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_execute(EHCIQueue *)", which dereferences it.</span> >qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2100:19: <b>deref_parm</b>: Directly dereferencing parameter "q". > ><a name='def685'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def685'>[#def685]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1010"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2263: <b>switch_case</b>: Reached case "1010"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2264: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_fetchqtd(EHCIQueue *)", which dereferences it.</span> >qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:1992:5: <b>deref_parm</b>: Directly dereferencing parameter "q". > ><a name='def686'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def686'>[#def686]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1013"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2267: <b>switch_case</b>: Reached case "1013"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2268: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_horizqh(EHCIQueue *)", which dereferences it.</span> >qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2054:5: <b>deref_parm</b>: Directly dereferencing parameter "q". > ><a name='def687'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def687'>[#def687]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1740: <b>cond_false</b>: Condition "class_id == 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1741: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num != bus_num", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1747: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num != bus_num", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_true</b>: Condition "f->port != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_true</b>: Condition "port == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>var_compare_op</b>: Comparing "port" to null implies that "port" might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1753: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num != bus_num", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_false</b>: Condition "f->port != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1754: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id != vendor_id", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1757: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num > 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_false</b>: Condition "f->port != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1754: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_false</b>: Condition "f->vendor_id != vendor_id", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1758: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1760: <b>cond_true</b>: Condition "f->product_id > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1760: <b>cond_false</b>: Condition "f->product_id != product_id", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1765: <b>cond_false</b>: Condition "s->errcount >= 3", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1767: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1770: <b>cond_false</b>: Condition "s->fd != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1772: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/usb/host-linux.c:1775: <b>var_deref_model</b>: Passing null pointer "port" to function "usb_host_open(USBHostDevice *, int, int, char const *, char const *, int)", which dereferences it. ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1293:5: <b>cond_false</b>: Condition "dev->fd != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1295:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1298:5: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1300:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1305:5: <b>deref_parm_in_call</b>: Function "strcpy(char * restrict, char const * restrict)" dereferences "port".</span> > ><a name='def688'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def688'>[#def688]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>cond_true</b>: Condition "index < s->mapping.next", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>cond_false</b>: Condition "mapping = array_get(&s->mapping, index)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1962: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>var_compare_op</b>: Comparing "mapping" to null implies that "mapping" might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1963: <b>cond_false</b>: Condition "index >= s->mapping.next", taking false branch</span> >qemu-kvm-1.2.0/block/vvfat.c:1963: <b>var_deref_op</b>: Dereferencing null pointer "mapping". > ><a name='def689'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def689'>[#def689]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_true</b>: Condition "*args == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1146: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>cond_true</b>: Condition "*args != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1143: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_false</b>: Condition "*args == ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1147: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1150: <b>cond_true</b>: Condition "__coverity_strncmp(args, "soft=", 5) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1163: <b>cond_false</b>: Condition "*args != '('", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1165: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1171: <b>cond_true</b>: Condition "type_params_length < 99UL /* sizeof (type_str) - 1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1178: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1180: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1182: <b>cond_true</b>: Condition "opts->vreader_count >= reader_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1186: <b>cond_false</b>: Condition "vreaderOpt == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1188: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>cond_true</b>: Condition "i < count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1205: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>cond_false</b>: Condition "i < count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1205: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1206: <b>cond_true</b>: Condition "*args == ')'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1211: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1247: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>cond_true</b>: Condition "*args != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1143: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_false</b>: Condition "*args == ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1147: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1150: <b>cond_true</b>: Condition "__coverity_strncmp(args, "soft=", 5) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1160: <b>assign_zero</b>: Assigning: "vreaderOpt" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1163: <b>cond_false</b>: Condition "*args != '('", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1165: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1171: <b>cond_true</b>: Condition "type_params_length < 99UL /* sizeof (type_str) - 1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1178: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1180: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1182: <b>cond_false</b>: Condition "opts->vreader_count >= reader_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1189: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1191: <b>alias_transfer</b>: Assigning: "vreaderOpt" = "vreaderOpt + opts->vreader_count".</span> >qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1192: <b>var_deref_op</b>: Dereferencing null pointer "vreaderOpt". > ><a name='def690'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def690'>[#def690]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "128"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:444: <b>switch_case</b>: Reached case "128"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:445: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def691'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def691'>[#def691]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "132"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:447: <b>switch_case</b>: Reached case "132"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:448: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def692'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def692'>[#def692]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "144"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:454: <b>switch_case</b>: Reached case "144"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:455: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def693'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def693'>[#def693]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "152"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:460: <b>switch_case</b>: Reached case "152"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:461: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def694'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def694'>[#def694]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "156"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:463: <b>switch_case</b>: Reached case "156"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:464: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def695'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def695'>[#def695]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "132"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:535: <b>switch_case</b>: Reached case "132"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:536: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def696'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def696'>[#def696]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "136"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:541: <b>switch_case</b>: Reached case "136"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:542: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def697'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def697'>[#def697]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "140"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:547: <b>switch_case</b>: Reached case "140"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:548: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def698'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def698'>[#def698]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "144"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:551: <b>switch_case</b>: Reached case "144"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:552: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def699'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def699'>[#def699]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "148"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:557: <b>switch_case</b>: Reached case "148"</span> >qemu-kvm-1.2.0/hw/omap_intc.c:558: <b>var_deref_op</b>: Dereferencing null pointer "bank". > ><a name='def700'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def700'>[#def700]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:659: <b>cond_true</b>: Condition "s->sizearg == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:660: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:663: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:669: <b>cond_true</b>: Condition "ivshmem_has_feature(s, 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:669: <b>cond_false</b>: Condition "!ivshmem_has_feature(s, 1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:676: <b>cond_true</b>: Condition "s->role", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:677: <b>cond_true</b>: Condition "__coverity_strncmp(s->role, "peer", 5) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:679: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:684: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:685: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:687: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:689: <b>cond_true</b>: Condition "s->role_val == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:711: <b>cond_true</b>: Condition "s->server_chr != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:711: <b>cond_false</b>: Condition "__coverity_strncmp(s->server_chr->filename, "unix:", 5) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:741: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:745: <b>cond_true</b>: Condition "s->shmobj == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:745: <b>var_compare_op</b>: Comparing "s->shmobj" to null implies that "s->shmobj" might be null.</span> >qemu-kvm-1.2.0/hw/ivshmem.c:753: <b>var_deref_model</b>: Passing null pointer "s->shmobj" to function "shm_open(char const *, int, mode_t)", which dereferences it. > ><a name='def701'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def701'>[#def701]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3538: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3540: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3544: <b>cond_true</b>: Condition "intel_syntax == -1 /* (char)-1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3545: <b>cond_false</b>: Condition "info->mach == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3545: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 3", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3552: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3556: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>cond_true</b>: Condition "p != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3560: <b>cond_true</b>: Condition "__coverity_strncmp(p, "x86-64", 6) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3564: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3608: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3611: <b>cond_false</b>: Condition "p != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3612: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3613: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>cond_false</b>: Condition "p != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3613: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3615: <b>cond_true</b>: Condition "intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3628: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3642: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_true</b>: Condition "i < 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_true</b>: Condition "i < 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_false</b>: Condition "i < 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3664: <b>cond_false</b>: Condition "_setjmp(priv.bailout) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3687: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3696: <b>cond_true</b>: Condition "*codep == 98", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_false</b>: Condition "prefixes & 0x800", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_true</b>: Condition "rex", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_false</b>: Condition "rex_used", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3711: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3714: <b>cond_false</b>: Condition "*codep == 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3748: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3754: <b>cond_false</b>: Condition "*codep == 144", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3759: <b>cond_true</b>: Condition "!uses_REPZ_prefix", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3759: <b>cond_true</b>: Condition "prefixes & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3764: <b>cond_true</b>: Condition "!uses_REPNZ_prefix", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3764: <b>cond_true</b>: Condition "prefixes & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3770: <b>cond_true</b>: Condition "!uses_LOCK_prefix", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3770: <b>cond_true</b>: Condition "prefixes & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3776: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3779: <b>cond_true</b>: Condition "dp->op[2].bytemode != 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3781: <b>cond_false</b>: Condition "sizeflag & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3781: <b>cond_true</b>: Condition "address_mode == mode_64bit", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3782: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3784: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3789: <b>cond_true</b>: Condition "!uses_DATA_prefix", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3789: <b>cond_true</b>: Condition "prefixes & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_true</b>: Condition "dp->op[2].bytemode == 9", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_true</b>: Condition "dp->op[0].bytemode == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_false</b>: Condition "!intel_syntax", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3801: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3804: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3804: <b>cond_true</b>: Condition "dp->op[0].bytemode == 5", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3810: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3817: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3819: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3819: <b>cond_false</b>: Condition "dp->op[0].bytemode == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3824: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3826: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3826: <b>var_compare_op</b>: Comparing "dp->name" to null implies that "dp->name" might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3828: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3861: <b>switch_default</b>: Reached default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3863: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3864: <b>switch_end</b>: Reached end of switch</span> >qemu-kvm-1.2.0/i386-dis.c:3867: <b>var_deref_model</b>: Passing null pointer "dp->name" to function "putop(char const *, int)", which dereferences it. ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4340:8: <b>var_assign_parm</b>: Assigning: "p" = "template".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4340:3: <b>deref_var</b>: Dereferencing "p" (which is a copy of "template").</span> > ><a name='def702'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def702'>[#def702]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:738: <b>cond_true</b>: Condition "l1_table_offset != s->l1_table_offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:739: <b>cond_false</b>: Condition "l1_size2 != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:741: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:742: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:745: <b>cond_false</b>: Condition "bdrv_pread(bs->file, l1_table_offset, l1_table, l1_size2) != l1_size2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:750: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:752: <b>cond_true</b>: Condition "i < l1_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:753: <b>var_deref_model</b>: Passing null pointer "l1_table + i" to function "be64_to_cpus(uint64_t *)", which dereferences it.</span> >qemu-kvm-1.2.0/bswap.h:130:1: <b>deref_parm</b>: Directly dereferencing parameter "p". > ><a name='def703'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def703'>[#def703]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:738: <b>cond_true</b>: Condition "l1_table_offset != s->l1_table_offset", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:739: <b>cond_false</b>: Condition "l1_size2 != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:741: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:742: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> >qemu-kvm-1.2.0/block/qcow2-refcount.c:745: <b>var_deref_model</b>: Passing null pointer "l1_table" to function "bdrv_pread(BlockDriverState *, int64_t, void *, int)", which dereferences it. ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1707:5: <b>cond_true</b>: Condition "len > count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1710:5: <b>cond_true</b>: Condition "len > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1711:9: <b>cond_false</b>: Condition "(ret = bdrv_read(bs, sector_num, tmp_buf, 1)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1712:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1713:9: <b>deref_parm_in_call</b>: Function "memcpy(void * restrict, void const * restrict, size_t)" dereferences "buf".</span> > ><a name='def704'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def704'>[#def704]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3623: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3625: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block.c:3623: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. > ><a name='def705'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def705'>[#def705]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:389: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:391: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block.c:389: <b>loop_condition</b>: If "cco.ret == 2147483647" is initially true then it will remain true. > ><a name='def706'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def706'>[#def706]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1626: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1628: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block.c:1626: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. > ><a name='def707'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def707'>[#def707]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3684: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3686: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block.c:3684: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. > ><a name='def708'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def708'>[#def708]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:298: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:300: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/qemu-io.c:298: <b>loop_condition</b>: If "async_ret == 2147483647" is initially true then it will remain true. > ><a name='def709'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def709'>[#def709]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:312: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:314: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/qemu-io.c:312: <b>loop_condition</b>: If "async_ret == 2147483647" is initially true then it will remain true. > ><a name='def710'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def710'>[#def710]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:270: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:272: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block/qed-table.c:270: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. > ><a name='def711'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def711'>[#def711]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:197: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:199: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block/qed-table.c:197: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. > ><a name='def712'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def712'>[#def712]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:292: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:294: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block/qed-table.c:292: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. > ><a name='def713'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def713'>[#def713]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:176: <b>loop_top</b>: Top of the loop.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:178: <b>loop_bottom</b>: Bottom of the loop.</span> >qemu-kvm-1.2.0/block/qed-table.c:176: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. > ><a name='def714'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def714'>[#def714]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1712: <b>unterminated_case</b>: This case (value 16) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/omap_dma.c:1714: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def715'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def715'>[#def715]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1710: <b>unterminated_case</b>: This case (value 20) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/omap_dma.c:1712: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def716'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def716'>[#def716]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1721: <b>unterminated_case</b>: This case (value 32) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/omap_dma.c:1723: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def717'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def717'>[#def717]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1719: <b>unterminated_case</b>: This case (value 36) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/omap_dma.c:1721: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def718'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def718'>[#def718]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4067: <b>unterminated_case</b>: This case (value 46) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/target-sparc/translate.c:4073: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def719'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def719'>[#def719]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap1.c:634: <b>unterminated_case</b>: This case (value 44) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/omap1.c:636: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def720'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def720'>[#def720]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:571: <b>unterminated_case</b>: This case (value 2) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/qemu-ga.c:576: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def721'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def721'>[#def721]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cirrus_vga.c:1308: <b>unterminated_case</b>: This case (value 7) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/cirrus_vga.c:1310: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def722'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def722'>[#def722]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:145: <b>unterminated_default</b>: The default case is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/pflash_cfi02.c:150: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def723'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def723'>[#def723]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/stellaris.c:182: <b>unterminated_case</b>: This case (value 72) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/stellaris.c:185: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def724'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def724'>[#def724]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:4406: <b>unterminated_case</b>: This case (value 130) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/target-i386/translate.c:4409: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def725'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def725'>[#def725]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7766: <b>unterminated_case</b>: This case (value 271) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/target-i386/translate.c:7769: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def726'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def726'>[#def726]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pxa2xx.c:414: <b>unterminated_case</b>: This case (value 100) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/pxa2xx.c:418: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def727'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def727'>[#def727]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3793: <b>unterminated_case</b>: This case (value 312) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/target-i386/translate.c:3796: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def728'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def728'>[#def728]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12282: <b>unterminated_case</b>: This case (value 1155530752) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/target-mips/translate.c:12284: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def729'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def729'>[#def729]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:282: <b>unterminated_case</b>: This case (value 17) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/twl92230.c:283: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def730'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def730'>[#def730]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:388: <b>unterminated_case</b>: This case (value 56) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/twl92230.c:389: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def731'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def731'>[#def731]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:489: <b>unterminated_case</b>: This case (value 19) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/twl92230.c:490: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def732'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def732'>[#def732]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:873: <b>unterminated_case</b>: This case (value 10) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/scsi-bus.c:878: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def733'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def733'>[#def733]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:887: <b>unterminated_case</b>: This case (value 15) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/scsi-bus.c:892: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def734'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def734'>[#def734]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cadence_ttc.c:341: <b>unterminated_case</b>: This case (value 56) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/cadence_ttc.c:344: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def735'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def735'>[#def735]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/cadence_ttc.c:346: <b>unterminated_case</b>: This case (value 68) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/cadence_ttc.c:349: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def736'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def736'>[#def736]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/m68k-dis.c:1627: <b>unterminated_case</b>: This case (value 88) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/m68k-dis.c:1629: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def737'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def737'>[#def737]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/hid.c:168: <b>unterminated_case</b>: This case (value 224) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/hid.c:173: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def738'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def738'>[#def738]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/hid.c:173: <b>unterminated_case</b>: This case (value 231) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/hid.c:178: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def739'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def739'>[#def739]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/jazz_led.c:164: <b>unterminated_case</b>: This case (value 16) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/jazz_led.c:167: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def740'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def740'>[#def740]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/sh_timer.c:73: <b>unterminated_case</b>: This case (value 3) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/sh_timer.c:76: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def741'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def741'>[#def741]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ohci.c:1704: <b>unterminated_case</b>: This case (value 24) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/usb/hcd-ohci.c:1707: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def742'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def742'>[#def742]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/es1370.c:540: <b>unterminated_case</b>: This case (value 40) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/es1370.c:542: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def743'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def743'>[#def743]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/es1370.c:538: <b>unterminated_case</b>: This case (value 44) is not terminated by a 'break' statement.</span> >qemu-kvm-1.2.0/hw/es1370.c:540: <b>fallthrough</b>: The above case falls through to this one. > ><a name='def744'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def744'>[#def744]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1113: <b>missing_lock</b>: Accessing "d->current_async" without holding lock "QemuMutex.lock". Elsewhere, "d->current_async" is accessed with "QemuMutex.lock" held 4 out of 5 times.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:834: <b>example_lock</b>: Locking "QemuMutex.lock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:836: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1500: <b>example_lock</b>: Locking "QemuMutex.lock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1507: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1650: <b>example_lock</b>: Locking "QemuMutex.lock".</span> >qemu-kvm-1.2.0/hw/qxl.c:1651: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held. > ><a name='def745'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def745'>[#def745]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:436: <b>missing_lock</b>: Accessing "aiocb->ret" without holding lock "lock". Elsewhere, "aiocb->ret" is accessed with "lock" held 3 out of 3 times.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:376: <b>example_lock</b>: Locking "lock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:377: <b>example_access</b>: "qemu_paiocb.ret" is accessed with lock "lock" held.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:571: <b>example_lock</b>: Locking "lock".</span> >qemu-kvm-1.2.0/posix-aio-compat.c:574: <b>example_access</b>: "qemu_paiocb.ret" is accessed with lock "lock" held. > ><a name='def746'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def746'>[#def746]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1923: <b>missing_lock</b>: Accessing "qxl->current_async" without holding lock "QemuMutex.lock". Elsewhere, "qxl->current_async" is accessed with "QemuMutex.lock" held 4 out of 5 times.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:834: <b>example_lock</b>: Locking "QemuMutex.lock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:836: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1500: <b>example_lock</b>: Locking "QemuMutex.lock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1507: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1650: <b>example_lock</b>: Locking "QemuMutex.lock".</span> >qemu-kvm-1.2.0/hw/qxl.c:1651: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held. > ><a name='def747'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def747'>[#def747]</a> >/tmp/tmp1Mua9_.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def748'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def748'>[#def748]</a> >/tmp/tmpmaaBfZ.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def749'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def749'>[#def749]</a> >/tmp/tmpxPCDO7.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def750'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def750'>[#def750]</a> >/tmp/tmp3md0Bm.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def751'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def751'>[#def751]</a> >/tmp/tmpVT2CXq.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def752'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def752'>[#def752]</a> >/tmp/tmpC9diCp.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def753'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def753'>[#def753]</a> >/tmp/tmp73vcGp.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def754'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def754'>[#def754]</a> >/tmp/tmpyrOepY.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def755'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def755'>[#def755]</a> >/tmp/tmplmBPNf.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def756'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def756'>[#def756]</a> >/tmp/tmpud3PK9.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def757'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def757'>[#def757]</a> >/tmp/tmp6xy3SA.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. > ><a name='def758'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def758'>[#def758]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:974: <b>cond_true</b>: Condition "__coverity_strcmp(protocol, "spice") == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:975: <b>negative_return_fn</b>: Function "monitor_get_fd(mon, fdname)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2391:5: <b>cond_true</b>: Condition "monfd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2394:9: <b>cond_true</b>: Condition "__coverity_strcmp(monfd->name, fdname) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2395:13: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2391:5: <b>cond_false</b>: Condition "monfd", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2408:5: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:975: <b>var_assign</b>: Assigning: signed variable "fd" = "monitor_get_fd(Monitor *, char const *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:978: <b>cond_false</b>: Condition "!using_spice", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:982: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:983: <b>cond_true</b>: Condition "qemu_spice_display_add_client(fd, skipauth, tls) < 0", taking true branch</span> >qemu-kvm-1.2.0/monitor.c:984: <b>negative_returns</b>: "fd" is passed to a parameter that cannot be negative. > ><a name='def759'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def759'>[#def759]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7902: <b>cond_true</b>: Condition "flags & (4UL /* 1 << 2 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7903: <b>cond_true</b>: Condition "dc->cpl == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7904: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7906: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "dc->tf", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "env->singlestep_enabled", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "flags & (8UL /* 1 << 3 */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_true</b>: Condition "flags & (4UL /* 1 << 2 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7947: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7950: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7954: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7955: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7955: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7956: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7957: <b>cond_true</b>: Condition "bp->pc == pc_ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7957: <b>cond_false</b>: Condition "bp->flags & 0x20", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7960: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7962: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7964: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7966: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7970: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-i386/translate.c:7971: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def760'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def760'>[#def760]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:10626: <b>negative_returns</b>: Passing negative constant "-1" to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6564:5: <b>switch</b>: Switch case value "OPC_ADD_S"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6565:10: <b>switch_case</b>: Reached case "OPC_ADD_S"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6571:13: <b>index</b>: Function "gen_load_fpr32(TCGv_i32, int)" uses "ft" as an array index.</span> >qemu-kvm-1.2.0/target-mips/translate.c:666:5: <b>index</b>: Indexing "NULL->active_fpu.fpr" with "reg". > ><a name='def761'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def761'>[#def761]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:577: <b>cond_true</b>: Condition "rom->path == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:582: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:586: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:588: <b>cond_true</b>: Condition "fw_dir", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:593: <b>negative_return_fn</b>: Function "lseek(fd, 0L, 2)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:593: <b>var_assign</b>: Assigning: unsigned variable "rom->romsize" = "lseek(int, __off64_t, int)".</span> >qemu-kvm-1.2.0/hw/loader.c:596: <b>negative_returns</b>: "rom->romsize" is passed to a parameter that cannot be negative. > ><a name='def762'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def762'>[#def762]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:77: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:78: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:79: <b>negative_return_fn</b>: Function "lseek(fd, 0L, 2)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:79: <b>var_assign</b>: Assigning: signed variable "size" = "lseek(int, __off64_t, int)".</span> >qemu-kvm-1.2.0/hw/loader.c:81: <b>negative_returns</b>: "size" is passed to a parameter that cannot be negative. > ><a name='def763'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def763'>[#def763]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2569: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2576: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2585: <b>cond_true</b>: Condition "tb->flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2590: <b>cond_true</b>: Condition "tb->flags & 16", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2591: <b>cond_true</b>: Condition "tb->flags & 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2596: <b>cond_true</b>: Condition "dc.icount", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2602: <b>cond_true</b>: Condition "env->singlestep_enabled", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2602: <b>cond_true</b>: Condition "env->exception_taken", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2611: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2613: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2618: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-xtensa/translate.c:2619: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def764'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def764'>[#def764]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:839: <b>cond_false</b>: Condition "addr & 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:840: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:843: <b>switch</b>: Switch case value "176UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:866: <b>switch_case</b>: Reached case "176UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:874: <b>negative_return_fn</b>: Function "IRQ_get_next(opp, &dst->raised)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:313:5: <b>cond_true</b>: Condition "q->next == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:313:5: <b>var_tested_neg</b>: Variable "q->next" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:318:5: <b>return_negative_variable</b>: Explicitly returning negative variable "q->next".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:874: <b>var_assign</b>: Assigning: signed variable "n_IRQ" = "IRQ_get_next(openpic_t *, IRQ_queue_t *)".</span> >qemu-kvm-1.2.0/hw/openpic.c:875: <b>negative_returns</b>: Using variable "n_IRQ" as an index to array "opp->src". > ><a name='def765'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def765'>[#def765]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:657: <b>negative_return_fn</b>: Function "ftell(f)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:657: <b>var_assign</b>: Assigning: signed variable "where" = "ftell(FILE *)".</span> >qemu-kvm-1.2.0/hw/pc.c:660: <b>negative_returns</b>: "where" is passed to a parameter that cannot be negative. > ><a name='def766'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def766'>[#def766]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9615: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9627: <b>cond_true</b>: Condition "env->hflags & (1UL /* 1 << 0 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9630: <b>cond_true</b>: Condition "!!(env->flags & POWERPC_FLAG_CFAR)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9633: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_SPE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9633: <b>cond_true</b>: Condition "(env->msr >> 25) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9634: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9636: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9637: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_VRE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9637: <b>cond_true</b>: Condition "(env->msr >> 25) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9638: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9640: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9641: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_SE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9641: <b>cond_true</b>: Condition "(env->msr >> 10) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9642: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9644: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9645: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_BE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9645: <b>cond_true</b>: Condition "(env->msr >> 9) & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9647: <b>cond_true</b>: Condition "!!env->singlestep_enabled", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9647: <b>cond_true</b>: Condition "!!env->singlestep_enabled", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9655: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9660: <b>cond_true</b>: Condition "ctx.exception == POWERPC_EXCP_NONE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9660: <b>cond_true</b>: Condition "gen_opc_ptr < gen_opc_end", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9661: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9661: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9662: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9663: <b>cond_true</b>: Condition "bp->pc == ctx.nip", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9665: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9667: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9669: <b>cond_true</b>: Condition "!!search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9669: <b>cond_true</b>: Condition "!!search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9671: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9675: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-ppc/translate.c:9676: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def767'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def767'>[#def767]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>var_tested_neg</b>: Variable "so->s" tests negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>cond_false</b>: Condition "so->extra", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/slirp/slirp.c:833: <b>negative_returns</b>: "so->s" is passed to a parameter that cannot be negative. > ><a name='def768'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def768'>[#def768]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1215: <b>cond_false</b>: Condition "!!!(s->csr[0] & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1218: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1244: <b>var_tested_neg</b>: Assigning: "s->xmit_pos" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> >qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>negative_returns</b>: Using variable "s->xmit_pos" as an index to array "s->buffer". > ><a name='def769'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def769'>[#def769]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1215: <b>cond_false</b>: Condition "!!!(s->csr[0] & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1218: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->csr[3] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1273: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_false</b>: Condition "!((tmd.status & 0x100) >> 8)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>cond_true</b>: Condition "s->xmit_pos >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1254: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1254: <b>cond_true</b>: Condition "!!(s->csr[3] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1260: <b>cond_true</b>: Condition "!!(s->csr[15] & 4)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1261: <b>cond_false</b>: Condition "(s->bcr[20] & 0xff) == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1263: <b>cond_true</b>: Condition "add_crc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1266: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1268: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1272: <b>var_tested_neg</b>: Assigning: "s->xmit_pos" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> >qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>negative_returns</b>: Using variable "s->xmit_pos" as an index to array "s->buffer". > ><a name='def770'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def770'>[#def770]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3370: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3395: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3400: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3400: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3401: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3402: <b>cond_true</b>: Condition "bp->pc == ctx.pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3404: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3406: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3408: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3410: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3414: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-alpha/translate.c:3415: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def771'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def771'>[#def771]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:326: <b>var_tested_neg</b>: Assigning: "rZ" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:328: <b>cond_false</b>: Condition "dc->format == OP_FMT_RI", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:331: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/target-lm32/translate.c:332: <b>negative_returns</b>: Using variable "rZ" as an index to array "cpu_R". > ><a name='def772'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def772'>[#def772]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1747: <b>cond_true</b>: Condition "!!(dc->tb_flags & (524288U /* 1 << 19 */))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1748: <b>cond_true</b>: Condition "dc->delayed_branch", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1757: <b>cond_false</b>: Condition "pc_start & 3", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1758: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1760: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1768: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1771: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1785: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1787: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1791: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-microblaze/translate.c:1792: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def773'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def773'>[#def773]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "46"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7675: <b>switch_case</b>: Reached case "46"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7676: <b>negative_return_fn</b>: Function "low2highgid(arg1)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4604:5: <b>cond_true</b>: Condition "(int16_t)gid == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4605:9: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> >qemu-kvm-1.2.0/linux-user/syscall.c:7676: <b>negative_returns</b>: "low2highgid(arg1)" is passed to a parameter that cannot be negative. > ><a name='def774'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def774'>[#def774]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7672: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7673: <b>negative_return_fn</b>: Function "low2highuid(arg1)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4596:5: <b>cond_true</b>: Condition "(int16_t)uid == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4597:9: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> >qemu-kvm-1.2.0/linux-user/syscall.c:7673: <b>negative_returns</b>: "low2highuid(arg1)" is passed to a parameter that cannot be negative. > ><a name='def775'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def775'>[#def775]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5123: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5130: <b>cond_true</b>: Condition "!(tb->flags & (1ULL /* 0x100000000ULL >> 32 */))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5145: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5152: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5152: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5153: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5154: <b>cond_true</b>: Condition "bp->pc == dc.pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5156: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5158: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5160: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5162: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5167: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-s390x/translate.c:5168: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def776'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def776'>[#def776]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_true</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking true branch</span> >qemu-kvm-1.2.0/slirp/socket.c:634: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. > ><a name='def777'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def777'>[#def777]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_false</b>: Condition "path", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:684: <b>negative_return_fn</b>: Function "mkstemp(un.sun_path)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:684: <b>var_assign</b>: Assigning: signed variable "fd" = "mkstemp(char *)".</span> >qemu-kvm-1.2.0/qemu-sockets.c:684: <b>negative_returns</b>: "fd" is passed to a parameter that cannot be negative. > ><a name='def778'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def778'>[#def778]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9708: <b>cond_true</b>: Condition "((tb->flags & (64UL /* 1 << 6 */)) >> 6) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9722: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9725: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9765: <b>cond_true</b>: Condition "dc->condexec_mask", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9782: <b>cond_true</b>: Condition "dc->pc >= 4294967280U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9782: <b>cond_false</b>: Condition "arm_feature(env, ARM_FEATURE_M)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9788: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9791: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9791: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9793: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9800: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9801: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>cond_false</b>: Condition "bp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9801: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9803: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9805: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9809: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-arm/translate.c:9810: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def779'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def779'>[#def779]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2989: <b>cond_true</b>: Condition "(env->sr & 8192) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2992: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2995: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3002: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3002: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3004: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3008: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3009: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>cond_false</b>: Condition "bp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3009: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3010: <b>cond_false</b>: Condition "dc->is_jmp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3011: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3013: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3015: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3019: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-m68k/translate.c:3020: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def780'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def780'>[#def780]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_false</b>: Condition "inso->so_state & 0x200", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:408: <b>cond_true</b>: Condition "(so = socreate(slirp)) == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:410: <b>negative_return_fn</b>: Function "accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" returns a negative number.</span> >qemu-kvm-1.2.0/slirp/tcp_subr.c:410: <b>negative_returns</b>: "accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" is passed to a parameter that cannot be negative. > ><a name='def781'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def781'>[#def781]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1928: <b>cond_true</b>: Condition "(env->sr & (1073741824U /* 1 << 30 */)) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1937: <b>var_tested_neg</b>: Assigning: "ii" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1940: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1943: <b>cond_true</b>: Condition "ctx.bstate == BS_NONE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1943: <b>cond_true</b>: Condition "gen_opc_ptr < gen_opc_end", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1944: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1944: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1945: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1946: <b>cond_true</b>: Condition "ctx.pc == bp->pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1951: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1953: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1955: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1957: <b>cond_false</b>: Condition "ii < i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1961: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-sh4/translate.c:1962: <b>negative_returns</b>: Using variable "ii" as an index to array "gen_opc_pc". > ><a name='def782'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def782'>[#def782]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:526: <b>negative_return_fn</b>: Function "target_mprotect(start, len, prot)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:94:5: <b>cond_true</b>: Condition "(start & 8191U /* ~~((1 << 13) - 1) */) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:95:9: <b>return_negative_constant</b>: Explicitly returning negative value "-22".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:526: <b>var_assign</b>: Assigning: unsigned variable "ret" = "target_mprotect(abi_ulong, abi_ulong, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527: <b>cond_true</b>: Condition "ret != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:528: <b>var_assign</b>: Assigning: unsigned variable "start" = "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:529: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:584: <b>negative_returns</b>: "start" is passed to a parameter that cannot be negative.</span> >qemu-kvm-1.2.0/exec.c:1076:5: <b>parm_loop_bound</b>: Using unsigned parameter "start" in a loop exit test. > ><a name='def783'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def783'>[#def783]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:253: <b>cond_true</b>: Condition "status < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:255: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:257: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:263: <b>negative_return_fn</b>: Function "v9fs_marshal(iovec, 1, 0UL, 0, "ddd", header.type, header.size, status)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_false</b>: Condition "copied < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:317:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:319:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_false</b>: Condition "copied < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:317:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:319:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_true</b>: Condition "copied < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>var_tested_neg</b>: Variable "copied" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:316:13: <b>return_negative_variable</b>: Explicitly returning negative variable "copied".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:263: <b>var_assign</b>: Assigning: signed variable "msg_size" = "v9fs_marshal(struct iovec *, int, size_t, int, char const *, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:265: <b>negative_returns</b>: "msg_size" is passed to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:159:5: <b>cond_true</b>: Condition "size", taking true branch</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:160:9: <b>neg_sink_parm_call</b>: Passing "size" to "write(int, void const *, size_t)", which cannot accept a negative number. > ><a name='def784'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def784'>[#def784]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12428: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12434: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12454: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12456: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12458: <b>cond_true</b>: Condition "ctx.bstate == BS_NONE", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12459: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12459: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12461: <b>cond_false</b>: Condition "bp->pc == ctx.pc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12469: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>cond_false</b>: Condition "bp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12470: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12473: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12475: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12479: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-mips/translate.c:12480: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def785'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def785'>[#def785]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1662: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> >qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. > ><a name='def786'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def786'>[#def786]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1228: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> >qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. > ><a name='def787'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def787'>[#def787]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2026: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> >qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. > ><a name='def788'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def788'>[#def788]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3189: <b>cond_true</b>: Condition "env->pregs[1] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3192: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3195: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3224: <b>cond_true</b>: Condition "!!(tb->flags & 7)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3225: <b>cond_true</b>: Condition "dc->delayed_branch", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3226: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3228: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3232: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3256: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3259: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3267: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3269: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3273: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3274: <b>cond_true</b>: Condition "dc->delayed_branch == 1", taking true branch</span> >qemu-kvm-1.2.0/target-cris/translate.c:3275: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def789'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def789'>[#def789]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3189: <b>cond_true</b>: Condition "env->pregs[1] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3192: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3195: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3224: <b>cond_false</b>: Condition "!!(tb->flags & 7)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3225: <b>cond_false</b>: Condition "dc->delayed_branch", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3228: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3232: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3256: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3259: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3267: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3269: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3273: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3274: <b>cond_false</b>: Condition "dc->delayed_branch == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3277: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/target-cris/translate.c:3277: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def790'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def790'>[#def790]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1968: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1971: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1985: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1985: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>cond_true</b>: Condition "bp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1987: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1996: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1997: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>cond_false</b>: Condition "bp", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1997: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1999: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:2001: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:2006: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-unicore32/translate.c:2007: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def791'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def791'>[#def791]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:364: <b>negative_return_fn</b>: Function "qemu_socket(2, 2, 0)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:364: <b>var_assign</b>: Assigning: signed variable "so->s" = "qemu_socket(int, int, int)".</span> >qemu-kvm-1.2.0/slirp/udp.c:372: <b>negative_returns</b>: "so->s" is passed to a parameter that cannot be negative. > ><a name='def792'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def792'>[#def792]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_true</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking true branch</span> >qemu-kvm-1.2.0/slirp/misc.c:139: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. > ><a name='def793'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def793'>[#def793]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> >qemu-kvm-1.2.0/slirp/misc.c:165: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. > ><a name='def794'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def794'>[#def794]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1685: <b>cond_true</b>: Condition "!!(dc->tb_flags & 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1687: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1693: <b>var_tested_neg</b>: Assigning: "k" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1697: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1705: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1707: <b>cond_false</b>: Condition "k < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1712: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-openrisc/translate.c:1713: <b>negative_returns</b>: Using variable "k" as an index to array "gen_opc_pc". > ><a name='def795'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def795'>[#def795]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:462: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:496: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> >qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. > ><a name='def796'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def796'>[#def796]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "parser", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "({...})", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "err", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "!obj", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "qobject_type(obj) != QTYPE_QDICT", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:522: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>cond_false</b>: Condition "qdict", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>cond_true</b>: Condition "({...})", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:529: <b>cond_false</b>: Condition "qdict_haskey(qdict, "execute")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:531: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:532: <b>cond_false</b>: Condition "!qdict_haskey(qdict, "error")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:539: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:540: <b>negative_return_fn</b>: Function "send_response(s, &qdict->base)" returns a negative number.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "payload", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "s->channel", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "({...})", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:456:5: <b>cond_false</b>: Condition "!payload_qstr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:458:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:460:5: <b>cond_true</b>: Condition "s->delimit_response", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:465:9: <b>cond_true</b>: Condition "payload_qstr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:466:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:468:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:473:5: <b>cond_true</b>: Condition "response_qstr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:474:5: <b>cond_true</b>: Condition "status != G_IO_STATUS_NORMAL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:475:9: <b>return_negative_constant</b>: Explicitly returning negative value "-5".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:540: <b>var_assign</b>: Assigning: signed variable "ret" = "send_response(GAState *, QObject *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:541: <b>cond_true</b>: Condition "ret", taking true branch</span> >qemu-kvm-1.2.0/qemu-ga.c:542: <b>negative_returns</b>: "ret" is passed to a parameter that cannot be negative. > ><a name='def797'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def797'>[#def797]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1028: <b>cond_false</b>: Condition "pc_start & 3", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1030: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1032: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1038: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1041: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1049: <b>cond_true</b>: Condition "search_pc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1051: <b>cond_false</b>: Condition "lj < j", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1056: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-lm32/translate.c:1057: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". > ><a name='def798'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def798'>[#def798]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_false</b>: Condition "*p", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:856: <b>cond_true</b>: Condition "nr_sep >= 2", taking true branch</span> >qemu-kvm-1.2.0/block/sheepdog.c:858: <b>returned_null</b>: Function "__coverity_strchr(char const *, int)" returns null (checked 51 out of 53 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:952: <b>example_assign</b>: Assigning: "e" = return value from "__coverity_strchr(p, 44)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:953: <b>example_checked</b>: "e" has its value checked in "e".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:281: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:282: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:85: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:86: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:214: <b>example_assign</b>: Assigning: "end" = return value from "__coverity_strchr(p, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:216: <b>example_checked</b>: "end" has its value checked in "end".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:871: <b>example_assign</b>: Assigning: "p" = return value from "__coverity_strchr(vdi, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:872: <b>example_checked</b>: "p" has its value checked in "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:858: <b>var_assigned</b>: Assigning: "p" = null return value from "__coverity_strchr(char const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:859: <b>dereference</b>: Incrementing a pointer which might be null: "p".</span> > ><a name='def799'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def799'>[#def799]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_false</b>: Condition "*p", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:856: <b>cond_true</b>: Condition "nr_sep >= 2", taking true branch</span> >qemu-kvm-1.2.0/block/sheepdog.c:862: <b>returned_null</b>: Function "__coverity_strchr(char const *, int)" returns null (checked 51 out of 53 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:952: <b>example_assign</b>: Assigning: "e" = return value from "__coverity_strchr(p, 44)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:953: <b>example_checked</b>: "e" has its value checked in "e".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:281: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:282: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:85: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:86: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:214: <b>example_assign</b>: Assigning: "end" = return value from "__coverity_strchr(p, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:216: <b>example_checked</b>: "end" has its value checked in "end".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:871: <b>example_assign</b>: Assigning: "p" = return value from "__coverity_strchr(vdi, 58)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:872: <b>example_checked</b>: "p" has its value checked in "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:862: <b>var_assigned</b>: Assigning: "p" = null return value from "__coverity_strchr(char const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:863: <b>dereference</b>: Incrementing a pointer which might be null: "p".</span> > ><a name='def800'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def800'>[#def800]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:853: <b>cond_false</b>: Condition "!nc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:856: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/net.c:859: <b>returned_null</b>: Function "qemu_opts_find(QemuOptsList *, char const *)" returns null (checked 9 out of 10 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:717:5: <b>cond_true</b>: Condition "opts", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:718:9: <b>cond_true</b>: Condition "!opts->id", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:719:13: <b>cond_false</b>: Condition "!id", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:721:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:722:13: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:728:5: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:717:5: <b>cond_false</b>: Condition "opts", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:728:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:729:5: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/device_tree.c:243: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/device_tree.c:244: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2482: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2483: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:354: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:355: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/microblaze_boot.c:111: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/microblaze_boot.c:112: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc/e500.c:145: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc/e500.c:146: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:859: <b>dereference</b>: Dereferencing a pointer that might be null "qemu_opts_find(qemu_find_opts_err("netdev", errp), id)" when calling "qemu_opts_del(QemuOpts *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:822:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:823:9: <b>deref_parm</b>: Directly dereferencing parameter "opts".</span> > ><a name='def801'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def801'>[#def801]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:594: <b>cond_false</b>: Condition "!ad->res_fis", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:594: <b>cond_false</b>: Condition "!(pr->cmd & (16U /* 1 << 4 */))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:596: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:598: <b>cond_true</b>: Condition "!cmd_fis", taking true branch</span> >qemu-kvm-1.2.0/hw/ide/ahci.c:601: <b>returned_null</b>: Function "dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)" returns null (checked 4 out of 5 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:178:5: <b>cond_false</b>: Condition "!dma_has_iommu(dma)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:186:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:187:9: <b>null_return</b>: Calling "iommu_dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)" which might return null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:397:5: <b>cond_false</b>: Condition "dma->map", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:399:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:403:5: <b>cond_true</b>: Condition "err", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:404:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:187:9: <b>return_null_fn</b>: Returning the return value of "iommu_dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)", which might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:158: <b>example_assign</b>: Assigning: "mem" = return value from "dma_memory_map(dbs->sg->dma, cur_addr, &cur_len, dbs->dir)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:159: <b>example_checked</b>: "mem" has its value checked in "mem".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:661: <b>example_checked</b>: "dma_memory_map(ad->hba->dma, prdt_addr, &prdt_len, DMA_DIRECTION_TO_DEVICE)" has its value checked in "prdt = dma_memory_map(ad->hba->dma, prdt_addr, &prdt_len, DMA_DIRECTION_TO_DEVICE)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:840: <b>example_assign</b>: Assigning: "cmd_fis" = return value from "dma_memory_map(s->dma, tbl_addr, &cmd_len, DMA_DIRECTION_FROM_DEVICE)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:843: <b>example_checked</b>: "cmd_fis" has its value checked in "cmd_fis".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/libhw.c:37: <b>example_assign</b>: Assigning: "mem" = return value from "dma_memory_map(sgl->dma, (sgl->sg + i).base, &len, dir)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/libhw.c:38: <b>example_checked</b>: "mem" has its value checked in "mem".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:601: <b>var_assigned</b>: Assigning: "cmd_fis" = null return value from "dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:609: <b>cond_true</b>: Condition "ad->hba->control_regs.irqstatus", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:613: <b>dereference</b>: Dereferencing a null pointer "cmd_fis".</span> > ><a name='def802'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def802'>[#def802]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "273"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8547: <b>switch_case</b>: Reached case "273"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8552: <b>cond_false</b>: Condition "arg5 != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8558: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8558: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_send(mqd_t, char const *, size_t, unsigned int)".</span> > ><a name='def803'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def803'>[#def803]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "273"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8547: <b>switch_case</b>: Reached case "273"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8552: <b>cond_true</b>: Condition "arg5 != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8554: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_timedsend(mqd_t, char const *, size_t, unsigned int, struct timespec const *)".</span> > ><a name='def804'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def804'>[#def804]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "274"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8563: <b>switch_case</b>: Reached case "274"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8569: <b>cond_false</b>: Condition "arg5 != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8575: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8575: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_receive(mqd_t, char *, size_t, unsigned int *)".</span> > ><a name='def805'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def805'>[#def805]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "274"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8563: <b>switch_case</b>: Reached case "274"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8569: <b>cond_true</b>: Condition "arg5 != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8571: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_timedreceive(mqd_t, char * restrict, size_t, unsigned int * restrict, struct timespec const * restrict)".</span> > ><a name='def806'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def806'>[#def806]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "271"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8529: <b>switch_case</b>: Reached case "271"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8533: <b>returned_null</b>: Function "lock_user_string(abi_ulong)" returns null (checked 8 out of 9 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>null_return</b>: Calling "lock_user(int, abi_ulong, long, int)" which might return null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_null_fn</b>: Returning the return value of "lock_user(int, abi_ulong, long, int)", which might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:627: <b>example_checked</b>: "lock_user_string(addr)" has its value checked in "(s = lock_user_string(addr)) != NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:236: <b>example_checked</b>: "lock_user_string(arg1)" has its value checked in "s = lock_user_string(arg1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:263: <b>example_assign</b>: Assigning: "p" = return value from "lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:265: <b>example_checked</b>: "p" has its value checked in "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:281: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8533: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user_string(abi_ulong)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8534: <b>cond_true</b>: Condition "arg4 != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8536: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_open(char const *, int, ...)".</span> > ><a name='def807'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def807'>[#def807]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "272"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8541: <b>switch_case</b>: Reached case "272"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:8542: <b>returned_null</b>: Function "lock_user_string(abi_ulong)" returns null (checked 8 out of 9 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>null_return</b>: Calling "lock_user(int, abi_ulong, long, int)" which might return null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_null_fn</b>: Returning the return value of "lock_user(int, abi_ulong, long, int)", which might be null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:627: <b>example_checked</b>: "lock_user_string(addr)" has its value checked in "(s = lock_user_string(addr)) != NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:236: <b>example_checked</b>: "lock_user_string(arg1)" has its value checked in "s = lock_user_string(arg1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:263: <b>example_assign</b>: Assigning: "p" = return value from "lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:265: <b>example_checked</b>: "p" has its value checked in "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:281: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8542: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user_string(abi_ulong)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8543: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_unlink(char const *)".</span> > ><a name='def808'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def808'>[#def808]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737481U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3473: <b>switch_case</b>: Reached case "3241737481U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3475: <b>alias</b>: Assigning: "gspec" = "argptr". Both pointers are now null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3481: <b>cond_true</b>: Condition "i < host_dm->target_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3486: <b>dereference</b>: Dereferencing a pointer that might be null "gspec" when calling "thunk_convert(void *, void const *, argtype const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:133:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:134:10: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:135:9: <b>deref_parm</b>: Directly dereferencing parameter "src".</span> > ><a name='def809'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def809'>[#def809]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737486U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3469: <b>switch_case</b>: Reached case "3241737486U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3471: <b>dereference</b>: Dereferencing a null pointer "argptr".</span> > ><a name='def810'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def810'>[#def810]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737477U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3464: <b>switch_case</b>: Reached case "3241737477U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3467: <b>dereference</b>: Dereferencing a pointer that might be null "argptr" when calling "memcpy(void * restrict, void const * restrict, size_t)".</span> > ><a name='def811'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def811'>[#def811]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737486U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3469: <b>switch_case</b>: Reached case "3241737486U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3470: <b>dereference</b>: Dereferencing a pointer that might be null "argptr" when calling "memcpy(void * restrict, void const * restrict, size_t)".</span> > ><a name='def812'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def812'>[#def812]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1934: <b>cond_true</b>: Condition "*s == 'p'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_true</b>: Condition "*s == 'm'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1942: <b>cond_false</b>: Condition "*s == 'M'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1942: <b>cond_false</b>: Condition "*s == 'z'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1953: <b>cond_true</b>: Condition "opcodep->match != 3583U /* 255 + 13 * 256 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1958: <b>cond_true</b>: Condition "opcodep->name[0] == 'j'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1960: <b>cond_true</b>: Condition "__coverity_strncmp(opcodep->name, "jsr", 3UL /* sizeof ("jsr") - 1 */) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1962: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1965: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'T'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1976: <b>switch_case</b>: Reached case "'T'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1978: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'N'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2053: <b>switch_case</b>: Reached case "'N'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "(insn & 15) == 15", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "prefix_opcodep == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2069: <b>cond_false</b>: Condition "opcodep->imm_oprnd_size == SIZE_FIX_32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2071: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2071: <b>cond_true</b>: Condition "opcodep->imm_oprnd_size == SIZE_SPEC_REG", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2079: <b>cond_true</b>: Condition "sregp == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2081: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2086: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2088: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2097: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2099: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2119: <b>switch_default</b>: Reached default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2125: <b>cond_true</b>: Condition "*cs == 'z'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2125: <b>cond_true</b>: Condition "insn & 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2128: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2156: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2157: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2410: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2411: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'N'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2053: <b>switch_case</b>: Reached case "'N'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_false</b>: Condition "(insn & 15) == 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2159: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2162: <b>cond_true</b>: Condition "info->insn_type != dis_nonbranch", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2171: <b>cond_false</b>: Condition "opcodep->imm_oprnd_size == SIZE_FIX_32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2173: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2173: <b>cond_true</b>: Condition "opcodep->imm_oprnd_size == SIZE_SPEC_REG", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2180: <b>cond_true</b>: Condition "sregp == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2181: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2183: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2184: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2186: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2193: <b>cond_false</b>: Condition "prefix_opcodep", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2400: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2406: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2411: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2423: <b>switch_case</b>: Reached case "'b'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2427: <b>cond_true</b>: Condition "where > 32767", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2430: <b>cond_true</b>: Condition "disdata->distype == cris_dis_v32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2432: <b>cond_true</b>: Condition "insn == 60927U /* (13 + 14 * 16) * 256 + 255 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2433: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2435: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2446: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'o'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2456: <b>switch_case</b>: Reached case "'o'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2461: <b>cond_true</b>: Condition "insn & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2464: <b>cond_true</b>: Condition "opcodep->match == 57344U /* (0 + 14 * 16) * 256 + 0 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2465: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2467: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2469: <b>cond_true</b>: Condition "disdata->distype == cris_dis_v32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'P'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2500: <b>switch_case</b>: Reached case "'P'"</span> >qemu-kvm-1.2.0/cris-dis.c:2503: <b>returned_null</b>: Function "spec_reg_info(unsigned int, enum cris_disass_family)" returns null (checked 5 out of 6 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_true</b>: Condition "cris_spec_regs[i].name != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1337:7: <b>cond_true</b>: Condition "cris_spec_regs[i].number == sreg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1339:4: <b>cond_true</b>: Condition "distype == cris_dis_v32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1340:6: <b>switch</b>: Switch case value "cris_ver_warning"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1342:13: <b>switch_case</b>: Reached case "cris_ver_warning"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1349:3: <b>cond_false</b>: Condition "cris_spec_regs[i].warning == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1350:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1353:8: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1355:6: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_true</b>: Condition "cris_spec_regs[i].name != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1337:7: <b>cond_true</b>: Condition "cris_spec_regs[i].number == sreg", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1339:4: <b>cond_true</b>: Condition "distype == cris_dis_v32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1340:6: <b>switch</b>: Switch case value "cris_ver_warning"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1342:13: <b>switch_case</b>: Reached case "cris_ver_warning"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1349:3: <b>cond_false</b>: Condition "cris_spec_regs[i].warning == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1350:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1353:8: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1355:6: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_false</b>: Condition "cris_spec_regs[i].name != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1359:3: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1850: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, distype)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1854: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1671: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info(spec_reg, disdata->distype)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1675: <b>example_checked</b>: "sregp" has its value checked in "sregp".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1700: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1714: <b>example_checked</b>: "sregp" has its value checked in "sregp != NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2074: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2079: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2176: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2180: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2503: <b>var_assigned</b>: Assigning: "sregp" = null return value from "spec_reg_info(unsigned int, enum cris_disass_family)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2505: <b>dereference</b>: Dereferencing a null pointer "sregp".</span> > ><a name='def813'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def813'>[#def813]</a> >qemu-kvm-1.2.0/block/vpc.c:665: <b>returned_null</b>: Function "get_option_parameter(QEMUOptionParameter *, char const *)" returns null (checked 10 out of 11 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list->name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:163:9: <b>cond_false</b>: Condition "!__coverity_strcmp(list->name, name)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:165:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:167:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_false</b>: Condition "list->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:167:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:169:5: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:667: <b>example_assign</b>: Assigning: "disk_type_param" = return value from "get_option_parameter(options, "subformat")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:668: <b>example_checked</b>: "disk_type_param" has its value checked in "disk_type_param".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3969: <b>example_assign</b>: Assigning: "backing_file" = return value from "get_option_parameter(param, "backing_file")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3970: <b>example_checked</b>: "backing_file" has its value checked in "backing_file".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-img.c:827: <b>example_assign</b>: Assigning: "out_baseimg_param" = return value from "get_option_parameter(param, "backing_file")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-img.c:828: <b>example_checked</b>: "out_baseimg_param" has its value checked in "out_baseimg_param".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:393: <b>example_checked</b>: "get_option_parameter(dest, list->name)" has its value checked in "get_option_parameter(dest, list->name) == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:267: <b>example_assign</b>: Assigning: "list" = return value from "get_option_parameter(list, name)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:268: <b>example_checked</b>: "list" has its value checked in "list == NULL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:665: <b>dereference</b>: Dereferencing a null pointer "get_option_parameter(options, "size")".</span> > ><a name='def814'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def814'>[#def814]</a> >qemu-kvm-1.2.0/target-sparc/cpu.c:647: <b>returned_null</b>: Function "strtok(char * restrict, char const * restrict)" returns null (checked 9 out of 10 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/acpi.c:118: <b>example_assign</b>: Assigning: "f" = return value from "strtok(NULL, ":")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/acpi.c:118: <b>example_checked</b>: "f" has its value checked in "f".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-timer.c:190: <b>example_assign</b>: Assigning: "name" = return value from "strtok(arg, ",")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-timer.c:191: <b>example_checked</b>: "name" has its value checked in "name".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/cpu.c:1020: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/cpu.c:911: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:663: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:664: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:731: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:664: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:647: <b>var_assigned</b>: Assigning: "name" = null return value from "strtok(char * restrict, char const * restrict)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:653: <b>cond_true</b>: Condition "i < 22UL /* sizeof (sparc_defs) / sizeof (sparc_defs[0]) */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:654: <b>dereference</b>: Dereferencing a pointer that might be null "name" when calling "strcasecmp(char const *, char const *)".</span> > ><a name='def815'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def815'>[#def815]</a> >qemu-kvm-1.2.0/linux-user/flatload.c:102: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:102: <b>var_assigned</b>: Assigning: "buf" = null return value from "lock_user(int, abi_ulong, long, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:103: <b>dereference</b>: Dereferencing a pointer that might be null "buf" when calling "pread(int, void *, size_t, __off64_t)".</span> > ><a name='def816'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def816'>[#def816]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:1322: <b>overrun-buffer-arg</b>: Overrunning struct type evt_encrypt_change of 4 bytes by passing it to a function which accesses it at byte offset 4 using argument "5".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:461:5: <b>cond_false</b>: Condition "!packet", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:462:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:464:5: <b>cond_true</b>: Condition "len", taking true branch</span> >qemu-kvm-1.2.0/hw/bt-hci.c:465:9: <b>access_dbuff_in_call</b>: Calling "memcpy(void * restrict, void const * restrict, size_t)" indexes array "params" with index "len". > ><a name='def817'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def817'>[#def817]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_false</b>: Condition "offset < 2048", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_at_least</b>: Checking "offset < 2048UL" implies that the value of "offset" is at least 2048 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>cond_true</b>: Condition "offset < 3072", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>cond_between</b>: Checking "offset < 3072UL" implies that the value of "offset" is between 2048 and 3071 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:290: <b>cond_false</b>: Condition "s->num_cpu == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:293: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:294: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:294: <b>assignment</b>: Assigning: "irq" = "offset - 2048UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:295: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:297: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:298: <b>cond_true</b>: Condition "irq >= 29", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:298: <b>cond_false</b>: Condition "irq <= 31", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:300: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:301: <b>overrun-local</b>: Overrunning array "s->irq_target" of 1020 4-byte elements at element index 1055 (byte offset 4220) using index "irq" (which evaluates to 1055). > ><a name='def818'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def818'>[#def818]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_true</b>: Condition "offset < 2048", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_between</b>: Checking "offset < 2048UL" implies that the value of "offset" is between 1024 and 2047 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:284: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:284: <b>assignment</b>: Assigning: "irq" = "offset - 1024UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:285: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:286: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:287: <b>cond_false</b>: Condition "irq < 32", taking false branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:287: <b>overrun-local</b>: Overrunning array "s->priority2" of 988 4-byte elements at element index 1023 (byte offset 4092) using index "irq - 32" (which evaluates to 1023). > ><a name='def819'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def819'>[#def819]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_true</b>: Condition "offset < 512", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_between</b>: Checking "offset < 512UL" implies that the value of "offset" is between 256 and 511 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:241: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:241: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:242: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL". The value of "irq" is now between 0 and 1016 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:242: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:244: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:245: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:245: <b>assignment</b>: Assigning: "irq" += "(s->revision == 4294967295U) ? 32 : 0". The value of "irq" is now between 32 and 1048 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:246: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:247: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:249: <b>assignment</b>: Assigning: "i" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:249: <b>cond_true</b>: Condition "i < 8", taking true branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:250: <b>overrun-local</b>: Overrunning array "s->irq_state" of 1020 8-byte elements at element index 1048 (byte offset 8384) using index "irq + i" (which evaluates to 1048). > ><a name='def820'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def820'>[#def820]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_false</b>: Condition "offset < 384", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_at_least</b>: Checking "offset < 384UL" implies that the value of "offset" is at least 384 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>cond_false</b>: Condition "offset < 640", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>cond_at_least</b>: Checking "offset < 640UL" implies that the value of "offset" is at least 640 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>cond_true</b>: Condition "offset < 2048", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>cond_between</b>: Checking "offset < 2048UL" implies that the value of "offset" is between 1024 and 2047 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:440: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:440: <b>assignment</b>: Assigning: "irq" = "offset - 1024UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:441: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:442: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:443: <b>cond_false</b>: Condition "irq < 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:445: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:446: <b>overrun-local</b>: Overrunning array "s->priority2" of 988 4-byte elements at element index 1023 (byte offset 4092) using index "irq - 32" (which evaluates to 1023). > ><a name='def821'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def821'>[#def821]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1048 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:370: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:371: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:372: <b>cond_false</b>: Condition "irq < 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:373: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>assignment</b>: Assigning: "i" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:375: <b>cond_true</b>: Condition "value & (1 << i)", taking true branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:379: <b>overrun-local</b>: Overrunning array "s->irq_state" of 1020 8-byte elements at element index 1048 (byte offset 8384) using index "irq + i" (which evaluates to 1048). > ><a name='def822'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def822'>[#def822]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1048 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:370: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:371: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:372: <b>cond_false</b>: Condition "irq < 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:373: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:375: <b>cond_true</b>: Condition "value & (1 << i)", taking true branch</span> >qemu-kvm-1.2.0/hw/arm_gic.c:376: <b>overrun-local</b>: Overrunning array "s->irq_target" of 1020 4-byte elements at element index 1048 (byte offset 4192) using index "irq" (which evaluates to 1048). > ><a name='def823'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def823'>[#def823]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_true</b>: Condition "r > 15", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:199: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:199: <b>cond_false</b>: Condition "r == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:202: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/target-cris/translate.c:202: <b>overrun-local</b>: Overrunning array "cpu_PR" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). > ><a name='def824'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def824'>[#def824]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:274: <b>cond_false</b>: Condition "c == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:275: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:276: <b>cond_true</b>: Condition "c == 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:279: <b>cond_true</b>: Condition "mon->outbuf_index >= 1023UL /* sizeof (mon->outbuf) - 1 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:279: <b>cond_at_least</b>: Checking "mon->outbuf_index >= 1023UL" implies that the value of "mon->outbuf_index" is at least 1023 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:282: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:274: <b>cond_false</b>: Condition "c == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:275: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:276: <b>cond_true</b>: Condition "c == 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:277: <b>incr</b>: Incrementing "mon->outbuf_index". The value of "mon->outbuf_index" is now at least 1024.</span> >qemu-kvm-1.2.0/monitor.c:278: <b>overrun-local</b>: Overrunning array "mon->outbuf" of 1024 bytes at byte offset 1024 using index "mon->outbuf_index++" (which evaluates to 1024). > ><a name='def825'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def825'>[#def825]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:56: <b>cond_false</b>: Condition "addr == 1008", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:58: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:60: <b>switch</b>: Switch case value "255"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:69: <b>switch_case</b>: Reached case "255"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:69: <b>equality_cond</b>: Jumping to case "255".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:71: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:92: <b>switch_end</b>: Reached end of switch</span> >qemu-kvm-1.2.0/hw/vt82c686.c:93: <b>overrun-local</b>: Overrunning array "superio_conf->config" of 255 bytes at byte offset 255 using index "superio_conf->index" (which evaluates to 255). > ><a name='def826'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def826'>[#def826]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:242: <b>cond_true</b>: Condition "bytes > s->prefetch.count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:251: <b>cond_false</b>: Condition "fptr < 64 - bytes", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:254: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:255: <b>cond_true</b>: Condition "fptr < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:255: <b>cond_at_most</b>: Checking "fptr < 64" implies that the value of "fptr" may be up to 63 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:256: <b>cond_true</b>: Condition "is16bit", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:258: <b>incr</b>: Incrementing "fptr". The value of "fptr" may now be up to 64.</span> >qemu-kvm-1.2.0/hw/omap_gpmc.c:259: <b>overrun-local</b>: Overrunning array "s->prefetch.fifo" of 64 bytes at byte offset 64 using index "fptr++" (which evaluates to 64). > ><a name='def827'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def827'>[#def827]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:674: <b>cond_true</b>: Condition "s->idx_in >= 4096UL /* sizeof (s->data_in) */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:674: <b>cond_at_least</b>: Checking "s->idx_in >= 4096UL" implies that the value of "s->idx_in" is at least 4096 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:677: <b>alias</b>: Assigning: "data" = "&s->data_in[s->idx_in]". "data" may now point to element 1024 (and beyond) of "s->data_in" (which consists of 1024 4-byte elements).</span> >qemu-kvm-1.2.0/hw/wm8750.c:680: <b>overrun-local</b>: Overrunning array of 1024 4-byte elements at element index 1024 (byte offset 4096) by dereferencing pointer "data". > ><a name='def828'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def828'>[#def828]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1157: <b>cond_false</b>: Condition "ptr & 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1159: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1178: <b>cond_true</b>: Condition "env->cr[4] & (512U /* 1 << 9 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1182: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1183: <b>assignment</b>: Assigning: "nb_xmm_regs" = "16".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1184: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1186: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1189: <b>cond_true</b>: Condition "!(env->efer & (16384UL /* 1 << 14 */))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1196: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_at_most</b>: Checking "i < nb_xmm_regs" implies that the value of "i" may be up to 15 on the true branch.</span> >qemu-kvm-1.2.0/target-i386/fpu_helper.c:1193: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). > ><a name='def829'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def829'>[#def829]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1095: <b>cond_false</b>: Condition "ptr & 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1097: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1127: <b>cond_true</b>: Condition "env->cr[4] & (512U /* 1 << 9 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1131: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1132: <b>assignment</b>: Assigning: "nb_xmm_regs" = "16".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1133: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1135: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1138: <b>cond_true</b>: Condition "!(env->efer & (16384UL /* 1 << 14 */))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1145: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_at_most</b>: Checking "i < nb_xmm_regs" implies that the value of "i" may be up to 15 on the true branch.</span> >qemu-kvm-1.2.0/target-i386/fpu_helper.c:1142: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). > ><a name='def830'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def830'>[#def830]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:274: <b>switch</b>: Switch case value "1256UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:303: <b>switch_case</b>: Reached case "1256UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:303: <b>equality_cond</b>: Jumping to case "1256UL".</span> >qemu-kvm-1.2.0/hw/musicpal.c:304: <b>overrun-local</b>: Overrunning array "s->tx_queue" of 2 4-byte elements at element index 2 (byte offset 8) using index "(offset - 1248UL) / 4UL" (which evaluates to 2). > ><a name='def831'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def831'>[#def831]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:316: <b>switch</b>: Switch case value "1256UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:357: <b>switch_case</b>: Reached case "1256UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:357: <b>equality_cond</b>: Jumping to case "1256UL".</span> >qemu-kvm-1.2.0/hw/musicpal.c:358: <b>overrun-local</b>: Overrunning array "s->tx_queue" of 2 4-byte elements at element index 2 (byte offset 8) using index "(offset - 1248UL) / 4UL" (which evaluates to 2). > ><a name='def832'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def832'>[#def832]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:206: <b>cond_false</b>: Condition "shift > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:208: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:206: <b>cond_at_most</b>: Checking "shift > 16" implies that the value of "shift" may be up to 16 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:209: <b>assignment</b>: Assigning: "i" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:209: <b>cond_true</b>: Condition "i < 16 - shift", taking true branch</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:210: <b>overrun-local</b>: Overrunning array "d->_b" of 16 bytes at byte offset 16 using index "i + shift" (which evaluates to 16). > ><a name='def833'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def833'>[#def833]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:298: <b>assignment</b>: Assigning: "quality" = "vs->tight.quality".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:300: <b>cond_false</b>: Condition "!vs->vd->lossy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:302: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "ds_get_bytes_per_pixel(vs->ds) == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "vs->clientds.pf.bytes_per_pixel == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "w < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "h < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:308: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:310: <b>cond_false</b>: Condition "vs->tight.quality != 255 /* (uint8_t)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:314: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:315: <b>cond_false</b>: Condition "w * h < tight_conf[compression].gradient_min_rect_size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:320: <b>cond_true</b>: Condition "vs->clientds.pf.bytes_per_pixel == 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:321: <b>cond_false</b>: Condition "vs->tight.pixel24", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:327: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:330: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:332: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:333: <b>cond_true</b>: Condition "quality != -1", taking true branch</span> >qemu-kvm-1.2.0/ui/vnc-enc-tight.c:334: <b>overrun-local</b>: Overrunning array "tight_conf" of 10 56-byte elements at element index 255 (byte offset 14280) using index "quality" (which evaluates to 255). > ><a name='def834'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def834'>[#def834]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:526: <b>cond_false</b>: Condition "dtype == 536870912", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>cond_true</b>: Condition "dtype == (537919488U /* 0x20000000 | 0x100000 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_true</b>: Condition "tp->size == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_const</b>: Checking "tp->size == 0" implies that the value of "tp->size" is 0 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:551: <b>cond_true</b>: Condition "txd_lower & 67108864", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:552: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:555: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "vlan_enabled(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "is_vlan_txd(txd_lower)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->tse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:572: <b>cond_true</b>: Condition "tp->size + bytes > msh", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_true</b>: Condition "65536UL /* sizeof (tp->data) */ - tp->size < bytes", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_at_least</b>: Checking "65536UL - tp->size < bytes" implies that the value of "bytes" is at least 65537 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>assignment</b>: Assigning: "bytes" = "(65536UL - tp->size < bytes) ? 65536UL - tp->size : bytes". The value of "bytes" is now 65536.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>assignment</b>: Assigning: "sz" = "tp->size + bytes". The value of "sz" is now 65536.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_false</b>: Condition "(sz = tp->size + bytes) >= hdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:578: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_at_least</b>: Checking "(sz = tp->size + bytes) >= hdr" implies that the value of "hdr" is at least 65537 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:581: <b>cond_true</b>: Condition "sz == msh", taking true branch</span> >qemu-kvm-1.2.0/hw/e1000.c:583: <b>overrun-buffer-arg</b>: Overrunning array "tp->data" of 65536 bytes by passing it to a function which accesses it at byte offset 65536 using argument "hdr" (which evaluates to 65537). > ><a name='def835'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def835'>[#def835]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:526: <b>cond_false</b>: Condition "dtype == 536870912", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>cond_true</b>: Condition "dtype == (537919488U /* 0x20000000 | 0x100000 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_true</b>: Condition "tp->size == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_const</b>: Checking "tp->size == 0" implies that the value of "tp->size" is 0 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:551: <b>cond_true</b>: Condition "txd_lower & 67108864", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:552: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:555: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "vlan_enabled(s)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "is_vlan_txd(txd_lower)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->tse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:572: <b>cond_true</b>: Condition "tp->size + bytes > msh", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_true</b>: Condition "65536UL /* sizeof (tp->data) */ - tp->size < bytes", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_true</b>: Condition "(sz = tp->size + bytes) >= hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_true</b>: Condition "tp->size < hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_between</b>: Checking "tp->size < hdr" implies that the value of "hdr" is between 1 and 65536 (inclusive) on the true branch.</span> >qemu-kvm-1.2.0/hw/e1000.c:578: <b>overrun-buffer-arg</b>: Overrunning array "tp->header" of 256 bytes by passing it to a function which accesses it at byte offset 65535 using argument "hdr" (which evaluates to 65536). > ><a name='def836'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def836'>[#def836]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:756: <b>assignment</b>: Assigning: "size" = "0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:758: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:762: <b>cond_false</b>: Condition "tcb_bytes > 2600", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:765: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:766: <b>cond_false</b>: Condition "tcb_bytes > 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:766: <b>cond_true</b>: Condition "tbd_array != 4294967295U", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:769: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:770: <b>cond_true</b>: Condition "tcb_bytes <= 2600UL /* sizeof (buf) */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:771: <b>cond_false</b>: Condition "size < tcb_bytes", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:784: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:785: <b>cond_false</b>: Condition "tbd_array == 4294967295U", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:787: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:790: <b>cond_true</b>: Condition "s->has_extended_tcb_support", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:790: <b>cond_true</b>: Condition "!(s->configuration[6] & (16 /* 1 << 4 */))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:792: <b>cond_true</b>: Condition "tbd_count < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:800: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>cond_false</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>cond_at_least</b>: Checking "tx_buffer_size < 2600UL - size" implies that the value of "tx_buffer_size" is at least 2600 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>assignment</b>: Assigning: "tx_buffer_size" = "(tx_buffer_size < 2600UL - size) ? tx_buffer_size : (2600UL - size)". The value of "tx_buffer_size" is now 2600.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:806: <b>assignment</b>: Assigning: "size" += "tx_buffer_size". The value of "size" is now 2600.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:807: <b>cond_true</b>: Condition "tx_buffer_el & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:808: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:810: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>cond_true</b>: Condition "tbd_count < s->tx.tbd_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:818: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_false</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_at_least</b>: Checking "tx_buffer_size < 2600UL - size" implies that the value of "tx_buffer_size" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>assignment</b>: Assigning: "tx_buffer_size" = "(tx_buffer_size < 2600UL - size) ? tx_buffer_size : (2600UL - size)". The value of "tx_buffer_size" is now 0.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:824: <b>assignment</b>: Assigning: "size" += "tx_buffer_size". The value of "size" is now 2600.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:825: <b>cond_false</b>: Condition "tx_buffer_el & 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:827: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:828: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>cond_true</b>: Condition "tbd_count < s->tx.tbd_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:818: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_true</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:822: <b>overrun-local</b>: Overrunning array of 2600 bytes at byte offset 2600 by dereferencing pointer "&buf[size]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pci.h:605:5: <b>deref_parm_in_call</b>: Function "pci_dma_rw(PCIDevice *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pci.h:598:5: <b>deref_parm_in_call</b>: Function "dma_memory_rw(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:150:5: <b>deref_parm_in_call</b>: Function "dma_memory_rw_relaxed(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:121:5: <b>cond_false</b>: Condition "!dma_has_iommu(dma)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:126:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:127:9: <b>deref_parm_in_call</b>: Function "iommu_dma_memory_rw(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:318:5: <b>cond_true</b>: Condition "len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:320:9: <b>cond_true</b>: Condition "err", taking true branch</span> >qemu-kvm-1.2.0/dma-helpers.c:326:6: <b>deref_parm_in_call</b>: Function "memset(void *, int, size_t)" dereferences "buf". > ><a name='def837'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def837'>[#def837]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:203: <b>switch</b>: Switch case value "162"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:208: <b>switch_case</b>: Reached case "162"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:208: <b>equality_cond</b>: Jumping to case "162".</span> >qemu-kvm-1.2.0/hw/ppc405_uc.c:209: <b>overrun-local</b>: Overrunning array "pob->besr" of 2 4-byte elements at element index 2 (byte offset 8) using index "dcrn - 160" (which evaluates to 2). > ><a name='def838'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def838'>[#def838]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:225: <b>switch</b>: Switch case value "162"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:230: <b>switch_case</b>: Reached case "162"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:230: <b>equality_cond</b>: Jumping to case "162".</span> >qemu-kvm-1.2.0/hw/ppc405_uc.c:232: <b>overrun-local</b>: Overrunning array "pob->besr" of 2 4-byte elements at element index 2 (byte offset 8) using index "dcrn - 160" (which evaluates to 2). > ><a name='def839'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def839'>[#def839]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:543: <b>cond_false</b>: Condition "!(env->psw.mask & 0x100000000000000ULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:545: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_false</b>: Condition "env->ext_index < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_at_least</b>: Checking "env->ext_index < 0" implies that the value of "env->ext_index" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_false</b>: Condition "env->ext_index > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:549: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_between</b>: Checking "env->ext_index > 16" implies that the value of "env->ext_index" is between 0 and 16 (inclusive) on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:551: <b>alias</b>: Assigning: "q" = "&env->ext_queue[env->ext_index]". "q" may now point between elements 0 and 16 (inclusive) of "env->ext_queue" (which consists of 16 12-byte elements).</span> >qemu-kvm-1.2.0/target-s390x/helper.c:554: <b>overrun-local</b>: Overrunning array of 16 12-byte elements at element index 16 (byte offset 192) by dereferencing pointer "q". > ><a name='def840'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def840'>[#def840]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_true</b>: Condition "r > 15", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:210: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:210: <b>cond_false</b>: Condition "r == 3", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:212: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:213: <b>cond_false</b>: Condition "r == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:214: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:215: <b>cond_true</b>: Condition "dc->tb_flags & 512", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:215: <b>cond_false</b>: Condition "r == 15", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:217: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:217: <b>cond_false</b>: Condition "r == 13", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:218: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/target-cris/translate.c:219: <b>overrun-local</b>: Overrunning array "cpu_PR" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). > ><a name='def841'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def841'>[#def841]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_true</b>: Condition "r > 15", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> >qemu-kvm-1.2.0/target-cris/translate.c:171: <b>overrun-local</b>: Overrunning array "cpu_R" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). > ><a name='def842'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def842'>[#def842]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2028: <b>switch_case</b>: Reached case "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2029: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 12 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2033: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 12) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def843'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def843'>[#def843]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2028: <b>switch_case</b>: Reached case "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2029: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 12 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2034: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 12) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def844'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def844'>[#def844]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2009: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2013: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2013: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 14 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2014: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def845'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def845'>[#def845]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2037: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2038: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_false</b>: Condition "upper - j < validd", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 14 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2042: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def846'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def846'>[#def846]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2009: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_between</b>: Checking "j >= 0" implies that the value of "j" is between 0 and 14 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2012: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "j" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def847'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def847'>[#def847]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2018: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2019: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2019: <b>cond_between</b>: Checking "j >= 0" implies that the value of "j" is between 0 and 14 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2021: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "j" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> >qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". > ><a name='def848'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def848'>[#def848]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>cond_true</b>: Condition "i < number_of_entries", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:447: <b>cond_true</b>: Condition "i == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:448: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>cond_false</b>: Condition "i < number_of_entries", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:448: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>cond_true</b>: Condition "i < 26 * number_of_entries", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_true</b>: Condition "offset < 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:453: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:456: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>cond_true</b>: Condition "i < 26 * number_of_entries", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_true</b>: Condition "offset < 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_between</b>: Checking "offset < 10" implies that the value of "offset" is between 0 and 9 (inclusive) on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>assignment</b>: Assigning: "offset" = "1 + offset". The value of "offset" is now between 1 and 10 (inclusive).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:453: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block/vvfat.c:455: <b>overrun-local</b>: Overrunning array "entry->name" of 8 bytes at byte offset 10 using index "offset" (which evaluates to 10). > ><a name='def849'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def849'>[#def849]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_true</b>: Condition "is_dot", taking true branch</span> >qemu-kvm-1.2.0/block/vvfat.c:622: <b>overrun-buffer-arg</b>: Overrunning array "entry->name" of 8 bytes by passing it to a function which accesses it at byte offset 10 using argument "11UL". > ><a name='def850'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def850'>[#def850]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_false</b>: Condition "is_dot", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:625: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "filename[j] != '.'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_false</b>: Condition "filename[j] != '.'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:631: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>cond_true</b>: Condition "j > 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:634: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:640: <b>cond_true</b>: Condition "j > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "filename[j + 1 + i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "filename[j + 1 + i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_false</b>: Condition "filename[j + 1 + i]", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i == 10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "entry->name[i] == 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 10", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i == 7", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "entry->name[i] == 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 10", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 7", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_false</b>: Condition "i >= 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:655: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_false</b>: Condition "!is_long_name(entry1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_false</b>: Condition "!is_long_name(entry1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_true</b>: Condition "!is_long_name(entry1)", taking true branch</span> >qemu-kvm-1.2.0/block/vvfat.c:660: <b>overrun-buffer-arg</b>: Overrunning array "entry1->name" of 8 bytes by passing it to a function which accesses it at byte offset 10 using argument "11UL". > ><a name='def851'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def851'>[#def851]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:218: <b>cond_false</b>: Condition "cmdline[0] == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:219: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:221: <b>cond_true</b>: Condition "rs->hist_entry != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:225: <b>cond_false</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:227: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_true</b>: Condition "idx < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:232: <b>cond_false</b>: Condition "hist_entry == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:233: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:234: <b>cond_false</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:246: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:247: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_true</b>: Condition "idx < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_at_most</b>: Checking "idx < 64" implies that the value of "idx" may be up to 63 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:232: <b>cond_false</b>: Condition "hist_entry == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:233: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:234: <b>cond_true</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking true branch</span> >qemu-kvm-1.2.0/readline.c:238: <b>overrun-local</b>: Overrunning array of 512 bytes at byte offset 512 by dereferencing pointer "&rs->history[idx + 1]". > ><a name='def852'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def852'>[#def852]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_true</b>: Condition "f->is_write == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_false</b>: Condition "f->buf_index > 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:562: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_true</b>: Condition "f->buf_index >= 32768", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_false</b>: Condition "f->buf_index >= 32768", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:574: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_true</b>: Condition "f->buf_index >= 32768", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_at_least</b>: Checking "f->buf_index >= 32768" implies that the value of "f->buf_index" is at least 32768 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> >qemu-kvm-1.2.0/savevm.c:568: <b>overrun-local</b>: Overrunning array of 32768 bytes at byte offset 32768 by dereferencing pointer "&f->buf[f->buf_index]". > ><a name='def853'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def853'>[#def853]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737481U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3473: <b>switch_case</b>: Reached case "3241737481U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3478: <b>overrun-buffer-val</b>: Overrunning array "arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> >qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". > ><a name='def854'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def854'>[#def854]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3251: <b>overrun-buffer-val</b>: Overrunning array "extent_arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> >qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". > ><a name='def855'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def855'>[#def855]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3337: <b>cond_true</b>: Condition "arg_type[0] == TYPE_PTR", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3338: <b>cond_true</b>: Condition "ie->access == (3 /* 1 | 2 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3344: <b>cond_false</b>: Condition "!argptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3345: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3353: <b>overrun-buffer-val</b>: Overrunning array "ifreq_arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> >qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". > ><a name='def856'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def856'>[#def856]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:93: <b>return_constant</b>: Function call "cpu_mmu_index(env)" returns 4.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:93: <b>assignment</b>: Assigning: "mmu_idx" = "cpu_mmu_index(env)". The value of "mmu_idx" is now 4.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:94: <b>cond_true</b>: Condition "!!(env->tlb_table[mmu_idx][page_index].addr_code != (addr & (18446744073709543427UL /* ~((1 << 13) - 1) | 4 - 1 */)))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:94: <b>cond_true</b>: Condition "!!(env->tlb_table[mmu_idx][page_index].addr_code != (addr & (18446744073709543427UL /* ~((1 << 13) - 1) | 4 - 1 */)))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:96: <b>overrun-call</b>: Overrunning callee's array of size 2 by passing argument "mmu_idx" (which evaluates to 4) in call to "helper_ldl_cmmu(struct CPUARMState *, target_ulong, int)".</span> >qemu-kvm-1.2.0/softmmu_template.h:108:5: <b>index_parm</b>: Indexing "env->tlb_table" with "mmu_idx". > ><a name='def857'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def857'>[#def857]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:299: <b>assignment</b>: Assigning: "so->so_urgc" = "2048".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301: <b>cond_false</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>cond_false</b>: Condition "len > so->so_urgc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>cond_at_most</b>: Checking "len > so->so_urgc" implies that the value of "len" may be up to 2048 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:317: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:319: <b>cond_true</b>: Condition "n > so->so_urgc", taking true branch</span> >qemu-kvm-1.2.0/slirp/socket.c:320: <b>overrun-local</b>: Overrunning array of 2048 bytes at byte offset 2048 by dereferencing pointer "&buff[len]". > ><a name='def858'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def858'>[#def858]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:303: <b>cond_false</b>: Condition "!s->enable", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:304: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "s->in_len >= 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "plen < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "s->in_len >= s->in_hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "plen < s->in_hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_true</b>: Condition "s->in_len >= s->in_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:322: <b>assignment</b>: Assigning: "s->in_data" = "2147483647".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:324: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:325: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:326: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "s->in_len >= 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "plen < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "s->in_len >= s->in_hdr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_false</b>: Condition "plen < s->in_hdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:314: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_true</b>: Condition "s->in_len >= s->in_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_at_least</b>: Checking "s->in_len >= s->in_data" implies that the value of "s->in_len" is at least 2147483647 on the true branch.</span> >qemu-kvm-1.2.0/hw/bt-hci-csr.c:319: <b>overrun-local</b>: Overrunning array of 4096 bytes at byte offset 2147483647 by dereferencing pointer "&s->inpkt[s->in_len]". > ><a name='def859'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def859'>[#def859]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x800", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x80", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x40", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x10", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_true</b>: Condition "i < 6", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_true</b>: Condition "i < 6", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_false</b>: Condition "i < 6", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_true</b>: Condition "i < 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_true</b>: Condition "i < 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_false</b>: Condition "i < 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:287: <b>cond_true</b>: Condition "flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:288: <b>cond_true</b>: Condition "(unsigned int)env->cc_op < CC_OP_NB", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:289: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:291: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:306: <b>cond_true</b>: Condition "flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:310: <b>cond_true</b>: Condition "!env->fptags[i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:310: <b>cond_true</b>: Condition "!env->fptags[i]", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:323: <b>cond_false</b>: Condition "(i & 1) == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:326: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_true</b>: Condition "i < 8", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:323: <b>cond_true</b>: Condition "(i & 1) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:324: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:326: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_false</b>: Condition "i < 8", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:328: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:329: <b>assignment</b>: Assigning: "nb" = "16".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:329: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:331: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_true</b>: Condition "i < nb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:339: <b>cond_false</b>: Condition "(i & 1) == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:342: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:343: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_true</b>: Condition "i < nb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_at_most</b>: Checking "i < nb" implies that the value of "i" may be up to 15 on the true branch.</span> >qemu-kvm-1.2.0/target-i386/helper.c:333: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). > ><a name='def860'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def860'>[#def860]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:221: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:224: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:229: <b>alias</b>: Assigning: "cmsg" = "&msg_control.cmsg". "cmsg" now points to element 0 of "msg_control.cmsg" (which consists of 1 16-byte elements).</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:233: <b>overrun-buffer-arg</b>: Overrunning struct type cmsghdr of 0 bytes by passing it to a function which accesses it at byte offset 3 using argument "4UL". > ><a name='def861'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def861'>[#def861]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_false</b>: Condition "r < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_true</b>: Condition "r > 15", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> >qemu-kvm-1.2.0/target-cris/translate.c:177: <b>overrun-local</b>: Overrunning array "cpu_R" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). > ><a name='def862'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def862'>[#def862]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_true</b>: Condition "i < 512U /* 64 * 8 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_true</b>: Condition "i < 512U /* 64 * 8 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_at_most</b>: Checking "i < 512U" implies that the value of "i" may be up to 511 on the true branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:421: <b>illegal_address</b>: "&s->output_irq[i]" evaluates to an address that is at byte offset 4088 of an array of 512 bytes.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_false</b>: Condition "i < 512U /* 64 * 8 */", taking false branch</span> >qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop_end</b>: Reached end of loop > ><a name='def863'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def863'>[#def863]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:166: <b>cond_true</b>: Condition "invalidate", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:179: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>cond_true</b>: Condition "nextchr == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:182: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:186: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:188: <b>cond_false</b>: Condition "chr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:189: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:193: <b>cond_false</b>: Condition "chr == 410", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:201: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:208: <b>cond_true</b>: Condition "keycode == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:211: <b>cond_true</b>: Condition "nextchr != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:217: <b>cond_true</b>: Condition "keycode != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode >= (1026 /* 2 | 0x400 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode < 1035 /* (2 | 0x400) + 9 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:228: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:296: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:179: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>cond_true</b>: Condition "nextchr == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:182: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:186: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:188: <b>cond_false</b>: Condition "chr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:189: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:193: <b>cond_false</b>: Condition "chr == 410", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:201: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:208: <b>cond_true</b>: Condition "keycode == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:211: <b>cond_true</b>: Condition "nextchr != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:217: <b>cond_true</b>: Condition "keycode != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode >= (1026 /* 2 | 0x400 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_false</b>: Condition "keycode < 1035 /* (2 | 0x400) + 9 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:229: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:234: <b>cond_true</b>: Condition "kbd_layout", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:236: <b>cond_false</b>: Condition "chr < 511", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:237: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:236: <b>cond_at_least</b>: Checking "chr < 511" implies that the value of "chr" is at least 511 on the false branch.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:239: <b>cond_true</b>: Condition "keysym == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:240: <b>cond_false</b>: Condition "chr < 32", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:246: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:250: <b>cond_false</b>: Condition "keycode == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:251: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:257: <b>cond_false</b>: Condition "keycode == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:258: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:260: <b>cond_false</b>: Condition "is_graphic_console()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:289: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/ui/curses.c:290: <b>overrun-local</b>: Overrunning array "curses2qemu" of 511 4-byte elements at element index 511 (byte offset 2044) using index "chr" (which evaluates to 511). > ><a name='def864'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def864'>[#def864]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:251: <b>cond_true</b>: Condition "fp == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:254: <b>cond_false</b>: Condition "t == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:256: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:262: <b>alias</b>: Assigning: "fp->frag_link.next" = "&fp->frag_link". "fp->frag_link.next" now points to byte 0 of "fp->frag_link" (which consists of 16 bytes).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:266: <b>goto</b>: Jumping to label "insert"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:312: <b>label</b>: Reached label "insert"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>cond_true</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:321: <b>cond_false</b>: Condition "q->ipf_ip.ip_off != next", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:322: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:324: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>cond_false</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:324: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:325: <b>cond_false</b>: Condition "((struct ipasfrag *)q->ipf_link.prev)->ipf_ip.ip_tos & 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:326: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:335: <b>cond_false</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:339: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:347: <b>alias</b>: Assigning: "q" = "fp->frag_link.next". "q" now points to byte 0 of "fp->frag_link" (which consists of 16 bytes).</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:356: <b>cond_false</b>: Condition "m->m_hdr.mh_flags & 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:359: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:361: <b>alias</b>: Assigning: "ip" = "(char *)q + 16UL". "ip" now points to byte 16 of "fp->frag_link" (which consists of 16 bytes).</span> >qemu-kvm-1.2.0/slirp/ip_input.c:362: <b>overrun-local</b>: Overrunning array of 16 bytes at byte offset 16 by dereferencing pointer "ip". > ><a name='def865'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def865'>[#def865]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "1568UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:292: <b>switch_case</b>: Reached case "1568UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:292: <b>equality_cond</b>: Jumping to case "1568UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:293: <b>cond_false</b>: Condition "offset == 1540", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:295: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:296: <b>overrun-local</b>: Overrunning array "(*s).ddr" of 8 4-byte elements at element index 8 (byte offset 32) using index "(offset - 1536UL) / 4UL" (which evaluates to 8). > ><a name='def866'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def866'>[#def866]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "2064UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:299: <b>switch_case</b>: Reached case "2064UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:299: <b>equality_cond</b>: Jumping to case "2064UL".</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:300: <b>overrun-local</b>: Overrunning array "(*s).mio_func" of 4 4-byte elements at element index 4 (byte offset 16) using index "(offset - 2048UL) / 4UL" (which evaluates to 4). > ><a name='def867'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def867'>[#def867]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "468UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:268: <b>switch_case</b>: Reached case "468UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:268: <b>equality_cond</b>: Jumping to case "468UL".</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:269: <b>overrun-local</b>: Overrunning array "(*s).misc" of 9 4-byte elements at element index 9 (byte offset 36) using index "(offset - 432UL) / 4UL" (which evaluates to 9). > ><a name='def868'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def868'>[#def868]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "600UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:270: <b>switch_case</b>: Reached case "600UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:270: <b>equality_cond</b>: Jumping to case "600UL".</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:271: <b>overrun-local</b>: Overrunning array "(*s).reset" of 22 4-byte elements at element index 22 (byte offset 88) using index "(offset - 512UL) / 4UL" (which evaluates to 22). > ><a name='def869'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def869'>[#def869]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "1568UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:427: <b>switch_case</b>: Reached case "1568UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:427: <b>equality_cond</b>: Jumping to case "1568UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:428: <b>cond_false</b>: Condition "offset == 1540", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:430: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:431: <b>overrun-local</b>: Overrunning array "(*s).ddr" of 8 4-byte elements at element index 8 (byte offset 32) using index "(offset - 1536UL) / 4UL" (which evaluates to 8). > ><a name='def870'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def870'>[#def870]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "2064UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:436: <b>switch_case</b>: Reached case "2064UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:436: <b>equality_cond</b>: Jumping to case "2064UL".</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:437: <b>overrun-local</b>: Overrunning array "(*s).mio_func" of 4 4-byte elements at element index 4 (byte offset 16) using index "(offset - 2048UL) / 4UL" (which evaluates to 4). > ><a name='def871'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def871'>[#def871]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "468UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:391: <b>switch_case</b>: Reached case "468UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:391: <b>equality_cond</b>: Jumping to case "468UL".</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:392: <b>overrun-local</b>: Overrunning array "(*s).misc" of 9 4-byte elements at element index 9 (byte offset 36) using index "(offset - 432UL) / 4UL" (which evaluates to 9). > ><a name='def872'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def872'>[#def872]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "600UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:394: <b>switch_case</b>: Reached case "600UL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:394: <b>equality_cond</b>: Jumping to case "600UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:395: <b>cond_false</b>: Condition "offset == 592", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:397: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/zynq_slcr.c:398: <b>overrun-local</b>: Overrunning array "(*s).reset" of 22 4-byte elements at element index 22 (byte offset 88) using index "(offset - 512UL) / 4UL" (which evaluates to 22). > ><a name='def873'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def873'>[#def873]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>cond_true</b>: Condition "type != 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>cond_false</b>: Condition "type != 11", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:261: <b>cond_false</b>: Condition "!msrc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:270: <b>cond_false</b>: Condition "ip->ip_off & 0x1fff", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:273: <b>cond_false</b>: Condition "(ip->ip_src.s_addr & __bswap_32(268435455U /* ~(0xf << 28) */)) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:275: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:279: <b>cond_true</b>: Condition "ip->ip_p == IPPROTO_ICMP", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>cond_false</b>: Condition "icp->icmp_type > 18", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>cond_false</b>: Condition "icmp_flush[icp->icmp_type]", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:290: <b>cond_false</b>: Condition "!m", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:292: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:296: <b>cond_true</b>: Condition "new_m_size > m->m_hdr.mh_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:311: <b>cond_false</b>: Condition "minsize", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:312: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:312: <b>cond_true</b>: Condition "s_ip_len > 548U /* 576 - 28 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:313: <b>assignment</b>: Assigning: "s_ip_len" = "548U".</span> >qemu-kvm-1.2.0/slirp/ip_icmp.c:324: <b>overrun-buffer-arg</b>: Overrunning struct type ip of 20 bytes by passing it to a function which accesses it at byte offset 547 using argument "s_ip_len" (which evaluates to 548). > ><a name='def874'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def874'>[#def874]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1103: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1103: <b>var_assign</b>: Assigning: "sockfd" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1104: <b>cond_false</b>: Condition "sockfd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1107: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1111: <b>noescape</b>: Resource "sockfd" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1111: <b>cond_true</b>: Condition "connect(sockfd, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&helper}), size) < 0", taking true branch</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1113: <b>leaked_handle</b>: Handle variable "sockfd" going out of scope leaks the handle. > ><a name='def875'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def875'>[#def875]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>var_assign</b>: Assigning: "pidfd" = handle returned from "open(pidfile, 65, 384)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "pidfd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "lockf(pidfd, 2, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:252: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "ftruncate(int, __off64_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "ftruncate(pidfd, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "lseek(int, __off64_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_true</b>: Condition "lseek(pidfd, 0, 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:256: <b>goto</b>: Jumping to label "fail"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:266: <b>label</b>: Reached label "fail"</span> >qemu-kvm-1.2.0/qemu-ga.c:268: <b>leaked_handle</b>: Handle variable "pidfd" going out of scope leaks the handle. > ><a name='def876'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def876'>[#def876]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>var_assign</b>: Assigning: "pidfd" = handle returned from "open(pidfile, 65, 384)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "pidfd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "lockf(pidfd, 2, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:252: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "ftruncate(int, __off64_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "ftruncate(pidfd, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "lseek(int, __off64_t, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "lseek(pidfd, 0, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:257: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:259: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "write(int, void const *, size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:259: <b>cond_false</b>: Condition "write(pidfd, pidstr, strlen(pidstr)) != strlen(pidstr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:262: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-ga.c:264: <b>leaked_handle</b>: Handle variable "pidfd" going out of scope leaks the handle. > ><a name='def877'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def877'>[#def877]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:131: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:131: <b>var_assign</b>: Assigning: "nullfd" = handle returned from "open("/dev/null", 2)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:132: <b>cond_false</b>: Condition "nullfd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:134: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:136: <b>noescape</b>: Resource "nullfd" is not freed or pointed-to in function "dup2(int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:138: <b>cond_false</b>: Condition "nullfd != fd", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:140: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-ga.c:141: <b>leaked_handle</b>: Handle variable "nullfd" going out of scope leaks the handle. > ><a name='def878'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def878'>[#def878]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2600: <b>switch</b>: Switch case value "13"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2607: <b>switch_case</b>: Reached case "13"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2609: <b>alloc_arg</b>: "target_to_host_semarray(int, unsigned short **, abi_ulong)" allocates memory that is stored into "array".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2539:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2540:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2544:5: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2544:5: <b>var_assign</b>: Assigning: "*host_array" = "malloc(nsems * 2UL)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2547:5: <b>cond_true</b>: Condition "!array", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2610: <b>cond_true</b>: Condition "err", taking true branch</span> >qemu-kvm-1.2.0/linux-user/syscall.c:2611: <b>leaked_storage</b>: Variable "array" going out of scope leaks the storage it points to. > ><a name='def879'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def879'>[#def879]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:346: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:346: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(filename, 66, 384)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:347: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:349: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:350: <b>cond_false</b>: Condition "lockf(fd, 2, 0) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:353: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:355: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "write(int, void const *, size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:355: <b>cond_false</b>: Condition "write(fd, buffer, len) != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:358: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/os-posix.c:361: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. > ><a name='def880'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def880'>[#def880]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_true</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking true branch</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:717: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def881'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def881'>[#def881]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_true</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking true branch</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:721: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def882'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def882'>[#def882]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_true</b>: Condition "listen(sock, 1) < 0", taking true branch</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:725: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def883'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def883'>[#def883]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:728: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:729: <b>cond_true</b>: Condition "client < 0", taking true branch</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:731: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def884'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def884'>[#def884]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:728: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:729: <b>cond_false</b>: Condition "client < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:732: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:733: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def885'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def885'>[#def885]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>var_assign</b>: Assigning: "interp_name" = storage returned from "malloc(eppnt->p_filesz)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1769: <b>noescape</b>: Resource "interp_name" is not freed or pointed-to in function "memcpy(void * restrict, void const * restrict, size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1777: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1778: <b>cond_true</b>: Condition "interp_name[eppnt->p_filesz - 1] != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1780: <b>goto</b>: Jumping to label "exit_errmsg"</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1780: <b>leaked_storage</b>: Variable "interp_name" going out of scope leaks the storage it points to. > ><a name='def886'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def886'>[#def886]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>var_assign</b>: Assigning: "interp_name" = storage returned from "malloc(eppnt->p_filesz)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_false</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1772: <b>noescape</b>: Resource "interp_name" is not freed or pointed-to in function "pread(int, void *, size_t, __off64_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1774: <b>cond_true</b>: Condition "retval != eppnt->p_filesz", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1775: <b>goto</b>: Jumping to label "exit_perror"</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1775: <b>leaked_storage</b>: Variable "interp_name" going out of scope leaks the storage it points to. > ><a name='def887'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def887'>[#def887]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_VIRTIO_SERIAL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:129: <b>switch_case</b>: Reached case "GA_CHANNEL_VIRTIO_SERIAL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:130: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:130: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(path, 10242)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:135: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:138: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:147: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:148: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:151: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:152: <b>break</b>: Breaking from switch</span> >qemu-kvm-1.2.0/qga/channel-posix.c:152: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. > ><a name='def888'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def888'>[#def888]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_ISA_SERIAL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:154: <b>switch_case</b>: Reached case "GA_CHANNEL_ISA_SERIAL"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:156: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:156: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(path, 2306)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:157: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:160: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:161: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcgetattr(int, struct termios *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:175: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcflush(int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:176: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcsetattr(int, int, struct termios const *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:177: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:178: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:180: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:181: <b>break</b>: Breaking from switch</span> >qemu-kvm-1.2.0/qga/channel-posix.c:181: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. > ><a name='def889'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def889'>[#def889]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_UNIX_LISTEN"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:183: <b>switch_case</b>: Reached case "GA_CHANNEL_UNIX_LISTEN"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:184: <b>open_fn</b>: Returning handle opened by function "unix_listen(char const *, char *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:744:5: <b>cond_false</b>: Condition "optstr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:752:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:756:5: <b>open_fn</b>: Returning handle opened by function "unix_listen_opts(QemuOpts *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:663:5: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:663:5: <b>var_assign</b>: Assigning: "sock" = "qemu_socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664:5: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671:5: <b>cond_false</b>: Condition "path", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675:9: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:689:5: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:689:5: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&un}), 110U /* sizeof (un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:692:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:693:5: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:696:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:698:5: <b>return_handle</b>: Returning opened handle "sock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:756:5: <b>var_assign</b>: Assigning: "sock" = "unix_listen_opts(opts)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:758:5: <b>cond_true</b>: Condition "sock != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:758:5: <b>cond_true</b>: Condition "ostr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:759:9: <b>cond_false</b>: Condition "optstr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:761:5: <b>return_handle</b>: Returning opened handle "sock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:184: <b>var_assign</b>: Assigning: "fd" = handle returned from "unix_listen(path, NULL, strlen(path))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:185: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:188: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:189: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_listen_add(GAChannel *, int, bool)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:55:53: <b>noescape</b>: "ga_channel_listen_add(GAChannel *, int, bool)" does not free or save its handle parameter "listen_fd".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:190: <b>break</b>: Breaking from switch</span> >qemu-kvm-1.2.0/qga/channel-posix.c:190: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. > ><a name='def890'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def890'>[#def890]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "channel != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "({...})", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:33: <b>open_fn</b>: Returning handle opened by function "qemu_accept(int, struct sockaddr *, socklen_t *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:294:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:294:5: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:296:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:298:5: <b>open_fn</b>: Returning handle opened by function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:298:5: <b>var_assign</b>: Assigning: "ret" = "accept(s, __SOCKADDR_ARG({ .__sockaddr__ = addr}), addrlen)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:299:5: <b>cond_true</b>: Condition "ret >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:300:9: <b>noescape</b>: Resource "ret" is not freed or pointed-to in function "qemu_set_cloexec(int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:157:27: <b>noescape</b>: "qemu_set_cloexec(int)" does not free or save its handle parameter "fd".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:303:5: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:33: <b>var_assign</b>: Assigning: "client_fd" = handle returned from "qemu_accept(g_io_channel_unix_get_fd(channel), (struct sockaddr *)&addr, &addrlen)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:35: <b>cond_false</b>: Condition "client_fd == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:38: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>noescape</b>: Resource "client_fd" is not freed or pointed-to in function "fcntl(int, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:40: <b>noescape</b>: Resource "client_fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:41: <b>cond_false</b>: Condition "ret", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:44: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:49: <b>cond_false</b>: Condition "!accepted", taking false branch</span> >qemu-kvm-1.2.0/qga/channel-posix.c:49: <b>leaked_handle</b>: Handle variable "client_fd" going out of scope leaks the handle. > ><a name='def891'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def891'>[#def891]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:220: <b>open_fn</b>: Returning handle opened by function "unix_socket_outgoing(char const *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:192:5: <b>open_fn</b>: Returning handle opened by function "unix_connect(char const *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:771:5: <b>open_fn</b>: Returning handle opened by function "unix_connect_opts(QemuOpts *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:711:5: <b>cond_false</b>: Condition "NULL == path", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:714:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:716:5: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:716:5: <b>var_assign</b>: Assigning: "sock" = "qemu_socket(1, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:717:5: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:720:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:725:5: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:725:5: <b>cond_false</b>: Condition "connect(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&un}), 110U /* sizeof (un) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:729:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:731:5: <b>return_handle</b>: Returning opened handle "sock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:771:5: <b>var_assign</b>: Assigning: "sock" = "unix_connect_opts(opts)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:773:5: <b>return_handle</b>: Returning opened handle "sock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:192:5: <b>return_handle_fn</b>: Directly returning handle opened by "unix_connect(char const *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:220: <b>var_assign</b>: Assigning: "sock" = handle returned from "unix_socket_outgoing(sockpath)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:221: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:223: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:225: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "nbd_receive_negotiate(int, char const *, uint32_t *, off_t *, size_t *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:246:31: <b>noescape</b>: "nbd_receive_negotiate(int, char const *, uint32_t *, off_t *, size_t *)" does not free or save its handle parameter "csock".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:227: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:228: <b>goto</b>: Jumping to label "out"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:262: <b>label</b>: Reached label "out"</span> >qemu-kvm-1.2.0/qemu-nbd.c:264: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def892'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def892'>[#def892]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>var_assign</b>: Assigning: "s" = handle returned from "qemu_socket(2, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:165: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:166: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:168: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:169: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:170: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> >qemu-kvm-1.2.0/slirp/misc.c:171: <b>overwrite_var</b>: Overwriting handle "s" in "s = getdtablesize() - 1" leaks the handle. > ><a name='def893'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def893'>[#def893]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_false</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:839: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:843: <b>cond_false</b>: Condition "asprintf(&info->value->hardware_address, "%02x:%02x:%02x:%02x:%02x:%02x", (int)mac_addr[0], (int)mac_addr[1], (int)mac_addr[2], (int)mac_addr[3], (int)mac_addr[4], (int)mac_addr[5]) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:852: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:858: <b>cond_true</b>: Condition "ifa->ifa_addr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:858: <b>cond_true</b>: Condition "ifa->ifa_addr->sa_family == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:864: <b>cond_false</b>: Condition "!inet_ntop(2, p, addr4, 16U /* sizeof (addr4) */)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:869: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:874: <b>cond_true</b>: Condition "ifa->ifa_netmask", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:880: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:906: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:908: <b>cond_false</b>: Condition "!address_item", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:910: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "*address_list", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "(*address_list)->next", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:916: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "*address_list", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_false</b>: Condition "(*address_list)->next", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:916: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:918: <b>cond_false</b>: Condition "!*address_list", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:920: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_false</b>: Condition "!info", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:817: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(2, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "ioctl(int, unsigned long, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_true</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>goto</b>: Jumping to label "error"</span> >qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def894'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def894'>[#def894]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(2, 1, 0)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "ioctl(int, unsigned long, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_false</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:839: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:843: <b>cond_true</b>: Condition "asprintf(&info->value->hardware_address, "%02x:%02x:%02x:%02x:%02x:%02x", (int)mac_addr[0], (int)mac_addr[1], (int)mac_addr[2], (int)mac_addr[3], (int)mac_addr[4], (int)mac_addr[5]) == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:851: <b>goto</b>: Jumping to label "error"</span> >qemu-kvm-1.2.0/qga/commands-posix.c:851: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. > ><a name='def895'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def895'>[#def895]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:173: <b>switch</b>: Switch case value "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:177: <b>switch_case</b>: Reached case "2"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:178: <b>cond_false</b>: Condition "use_gdb_syscalls()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:182: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>cond_false</b>: Condition "!(p = lock_user_string(({...})))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:186: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>var_assign</b>: Assigning: "result" = handle returned from "open(p, translate_openflags(({...})), ({...}))".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:188: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:188: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:191: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:404: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:406: <b>cond_false</b>: Condition "__hptr = lock_user(1, __gaddr, 4L /* sizeof (uint32_t) */, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:406: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:407: <b>cond_false</b>: Condition "__hptr = lock_user(1, __gaddr, 4L /* sizeof (uint32_t) */, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:407: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/target-m68k/m68k-semi.c:408: <b>leaked_handle</b>: Handle variable "result" going out of scope leaks the handle. > ><a name='def896'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def896'>[#def896]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:104: <b>switch</b>: Switch case value "5"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:113: <b>switch_case</b>: Reached case "5"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:114: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> >qemu-kvm-1.2.0/linux-user/m68k-sim.c:114: <b>leaked_handle</b>: Ignoring handle opened by "open((char *)(unsigned long)tswap32(args[0]), translate_openflags(tswap32(args[1])), tswap32(args[2]))" leaks it. > ><a name='def897'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def897'>[#def897]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_pci.c:68: <b>deref_ptr</b>: Directly dereferencing pointer "phb".</span> >qemu-kvm-1.2.0/hw/spapr_pci.c:72: <b>check_after_deref</b>: Null-checking "phb" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def898'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def898'>[#def898]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:2722: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->chr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:482:5: <b>deref_parm_in_call</b>: Function "put_packet_binary(GDBState *, char const *, int)" dereferences "s->chr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:446:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_true</b>: Condition "i < len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_true</b>: Condition "i < len", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_false</b>: Condition "i < len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:460:9: <b>deref_parm_in_call</b>: Function "put_buffer(GDBState *, uint8_t const *, int)" dereferences "s->chr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:393:5: <b>deref_parm_in_call</b>: Function "qemu_chr_fe_write(CharDriverState *, uint8_t const *, int)" dereferences "s->chr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:160:5: <b>deref_parm</b>: Directly dereferencing parameter "s".</span> >qemu-kvm-1.2.0/gdbstub.c:2725: <b>check_after_deref</b>: Null-checking "s->chr" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def899'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def899'>[#def899]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_fimd.c:1252: <b>deref_ptr</b>: Directly dereferencing pointer "s".</span> >qemu-kvm-1.2.0/hw/exynos4210_fimd.c:1256: <b>check_after_deref</b>: Null-checking "s" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def900'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def900'>[#def900]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:446: <b>deref_ptr</b>: Directly dereferencing pointer "peer".</span> >qemu-kvm-1.2.0/qemu-sockets.c:508: <b>check_after_deref</b>: Null-checking "peer" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def901'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def901'>[#def901]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->req".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:692:5: <b>deref_parm</b>: Directly dereferencing parameter "req".</span> >qemu-kvm-1.2.0/hw/usb/dev-storage.c:433: <b>check_after_deref</b>: Null-checking "s->req" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def902'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def902'>[#def902]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:286: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->file".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:551:5: <b>deref_parm</b>: Directly dereferencing parameter "f".</span> >qemu-kvm-1.2.0/migration.c:287: <b>check_after_deref</b>: Null-checking "s->file" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def903'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def903'>[#def903]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/ui/keymaps.c:131: <b>deref_ptr_in_call</b>: Dereferencing pointer "rest".</span> >qemu-kvm-1.2.0/ui/keymaps.c:133: <b>check_after_deref</b>: Null-checking "rest" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. > ><a name='def904'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def904'>[#def904]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:430: <b>cond_true</b>: Condition "!tmpdir", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:432: <b>cond_false</b>: Condition "snprintf(filename, size, "%s/vl.XXXXXX", tmpdir) >= size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/block.c:434: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/block.c:435: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. > ><a name='def905'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def905'>[#def905]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2375: <b>cond_false</b>: Condition "!hpagesize", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2377: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2379: <b>cond_false</b>: Condition "memory < hpagesize", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2383: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2388: <b>cond_false</b>: Condition "asprintf(&filename, "%s/qemu_back_mem.XXXXXX", path) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2390: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/exec.c:2392: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. > ><a name='def906'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def906'>[#def906]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5052: <b>cond_true</b>: Condition "fake_open->filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5053: <b>cond_true</b>: Condition "!__coverity_strncmp(pathname, fake_open->filename, strlen(fake_open->filename))", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5055: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5057: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5059: <b>cond_true</b>: Condition "fake_open->filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5066: <b>cond_true</b>: Condition "!tmpdir", taking true branch</span> >qemu-kvm-1.2.0/linux-user/syscall.c:5069: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. > ><a name='def907'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def907'>[#def907]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_true</b>: Condition "path", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_false</b>: Condition "strlen(path)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> >qemu-kvm-1.2.0/qemu-sockets.c:684: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. > ><a name='def908'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def908'>[#def908]</a> >qemu-kvm-1.2.0/hw/omap_dma.c:1267: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def909'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def909'>[#def909]</a> >qemu-kvm-1.2.0/hw/omap_dma.c:1277: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def910'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def910'>[#def910]</a> >qemu-kvm-1.2.0/hw/omap_dma.c:1287: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def911'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def911'>[#def911]</a> >qemu-kvm-1.2.0/hw/omap_dma.c:1297: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def912'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def912'>[#def912]</a> >qemu-kvm-1.2.0/hw/omap_dma.c:1045: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def913'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def913'>[#def913]</a> >qemu-kvm-1.2.0/hw/omap1.c:2704: <b>sign_extension</b>: Suspicious implicit sign extension: "from_bcd(value)" with type "unsigned char" (8 bits, unsigned) is promoted in "from_bcd(value) * 31536000" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "from_bcd(value) * 31536000" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def914'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def914'>[#def914]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:204: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[38]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[38]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def915'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def915'>[#def915]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:223: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[38]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[38]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def916'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def916'>[#def916]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:243: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[23]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[23]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def917'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def917'>[#def917]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:381: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[11]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[11] << 16) | s->regs[10]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[11] << 16) | s->regs[10]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def918'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def918'>[#def918]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:355: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def919'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def919'>[#def919]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:390: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def920'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def920'>[#def920]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:424: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def921'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def921'>[#def921]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:431: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def922'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def922'>[#def922]</a> >qemu-kvm-1.2.0/hw/megasas.c:391: <b>sign_extension</b>: Suspicious implicit sign extension: "id" with type "unsigned short" (16 bits, unsigned) is promoted in "id << 24" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "id << 24" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def923'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def923'>[#def923]</a> >qemu-kvm-1.2.0/hw/fdc.c:136: <b>sign_extension</b>: Suspicious implicit sign extension: "parse->last_sect" with type "unsigned char" (8 bits, unsigned) is promoted in "(parse->max_head + 1) * parse->max_track * parse->last_sect" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(parse->max_head + 1) * parse->max_track * parse->last_sect" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def924'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def924'>[#def924]</a> >qemu-kvm-1.2.0/cris-dis.c:2114: <b>sign_extension</b>: Suspicious implicit sign extension: "buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def925'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def925'>[#def925]</a> >qemu-kvm-1.2.0/cris-dis.c:2331: <b>sign_extension</b>: Suspicious implicit sign extension: "prefix_buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def926'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def926'>[#def926]</a> >qemu-kvm-1.2.0/cris-dis.c:2025: <b>sign_extension</b>: Suspicious implicit sign extension: "buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def927'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def927'>[#def927]</a> >qemu-kvm-1.2.0/cris-dis.c:2217: <b>sign_extension</b>: Suspicious implicit sign extension: "prefix_buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def928'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def928'>[#def928]</a> >qemu-kvm-1.2.0/m68k-dis.c:4693: <b>sign_extension</b>: Suspicious implicit sign extension: "data[cur_byte]" with type "unsigned char" (8 bits, unsigned) is promoted in "data[cur_byte] << cur_bitshift" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "data[cur_byte] << cur_bitshift" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def929'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def929'>[#def929]</a> >qemu-kvm-1.2.0/hw/lan9118.c:1159: <b>sign_extension</b>: Suspicious implicit sign extension: "s->write_word_h" with type "unsigned short" (16 bits, unsigned) is promoted in "s->write_word_l + (s->write_word_h << 16)" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "s->write_word_l + (s->write_word_h << 16)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def930'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def930'>[#def930]</a> >qemu-kvm-1.2.0/hw/qxl-render.c:199: <b>sign_extension</b>: Suspicious implicit sign extension: "cursor->header.height" with type "unsigned short" (16 bits, unsigned) is promoted in "cursor->header.width * cursor->header.height" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "cursor->header.width * cursor->header.height" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def931'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def931'>[#def931]</a> >qemu-kvm-1.2.0/hw/qxl-render.c:199: <b>sign_extension</b>: Suspicious implicit sign extension: "cursor->header.width" with type "unsigned short" (16 bits, unsigned) is promoted in "cursor->header.width * cursor->header.height" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "cursor->header.width * cursor->header.height" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def932'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def932'>[#def932]</a> >qemu-kvm-1.2.0/hw/mcf_fec.c:235: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "(s->conf.macaddr.a[0] << 24) | (s->conf.macaddr.a[1] << 16) | (s->conf.macaddr.a[2] << 8) | s->conf.macaddr.a[3]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->conf.macaddr.a[0] << 24) | (s->conf.macaddr.a[1] << 16) | (s->conf.macaddr.a[2] << 8) | s->conf.macaddr.a[3]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def933'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def933'>[#def933]</a> >qemu-kvm-1.2.0/hw/mcf_fec.c:239: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[4]" with type "unsigned char" (8 bits, unsigned) is promoted in "(s->conf.macaddr.a[4] << 24) | (s->conf.macaddr.a[5] << 16) | 0x8808" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->conf.macaddr.a[4] << 24) | (s->conf.macaddr.a[5] << 16) | 0x8808" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def934'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def934'>[#def934]</a> >qemu-kvm-1.2.0/hw/stellaris_enet.c:173: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "s->conf.macaddr.a[0] | (s->conf.macaddr.a[1] << 8) | (s->conf.macaddr.a[2] << 16) | (s->conf.macaddr.a[3] << 24)" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "s->conf.macaddr.a[0] | (s->conf.macaddr.a[1] << 8) | (s->conf.macaddr.a[2] << 16) | (s->conf.macaddr.a[3] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def935'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def935'>[#def935]</a> >qemu-kvm-1.2.0/arm-dis.c:4041: <b>sign_extension</b>: Suspicious implicit sign extension: "b[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "b[3] | (b[2] << 8) | (b[1] << 16) | (b[0] << 24)" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "b[3] | (b[2] << 8) | (b[1] << 16) | (b[0] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def936'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def936'>[#def936]</a> >qemu-kvm-1.2.0/arm-dis.c:4039: <b>sign_extension</b>: Suspicious implicit sign extension: "b[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "b[0] | (b[1] << 8) | (b[2] << 16) | (b[3] << 24)" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "b[0] | (b[1] << 8) | (b[2] << 16) | (b[3] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def937'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def937'>[#def937]</a> >qemu-kvm-1.2.0/microblaze-dis.c:773: <b>sign_extension</b>: Suspicious implicit sign extension: "ibytes[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "(ibytes[0] << 24) | (ibytes[1] << 16) | (ibytes[2] << 8) | ibytes[3]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(ibytes[0] << 24) | (ibytes[1] << 16) | (ibytes[2] << 8) | ibytes[3]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def938'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def938'>[#def938]</a> >qemu-kvm-1.2.0/microblaze-dis.c:775: <b>sign_extension</b>: Suspicious implicit sign extension: "ibytes[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "(ibytes[3] << 24) | (ibytes[2] << 16) | (ibytes[1] << 8) | ibytes[0]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(ibytes[3] << 24) | (ibytes[2] << 16) | (ibytes[1] << 8) | ibytes[0]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def939'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def939'>[#def939]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:751: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def940'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def940'>[#def940]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:805: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def941'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def941'>[#def941]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:809: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def942'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def942'>[#def942]</a> >qemu-kvm-1.2.0/hw/dp8393x.c:818: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. > ><a name='def943'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def943'>[#def943]</a> >qemu-kvm-1.2.0/target-ppc/translate_init.c:9649: <b>suspicious_sizeof</b>: Passing argument "1024UL /* 32 * sizeof (opc_handler_t) */" to function "malloc(size_t)" and then casting the return value to "opc_handler_t **" is suspicious. > ><a name='def944'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def944'>[#def944]</a> >qemu-kvm-1.2.0/block/vvfat.c:2849: <b>suspicious_sizeof</b>: Passing argument "8UL /* sizeof (void *) */" to function "g_malloc(gsize)" which returns a value of type "void *" is suspicious. > ><a name='def945'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def945'>[#def945]</a> >qemu-kvm-1.2.0/hw/qxl.c:238: <b>suspicious_sizeof</b>: Passing argument "qxl->guest_surfaces.cmds" of type "QXLPHYSICAL *" and argument "8UL /* sizeof (qxl->guest_surfaces.cmds) */ * qxl->ssd.num_surfaces" to function "memset(void *, int, size_t)" is suspicious. Did you intend to use "sizeof(*qxl->guest_surfaces.cmds)" instead of "sizeof (qxl->guest_surfaces.cmds)" ? In this particular case sizeof(QXLPHYSICAL *) happens to be equal to sizeof(QXLPHYSICAL), but this is not a portable assumption. > ><a name='def946'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def946'>[#def946]</a> >qemu-kvm-1.2.0/hw/qxl.c:952: <b>suspicious_sizeof</b>: Passing argument "caps" of type "uint8_t *" and argument "8UL /* sizeof (caps) */" to function "memcpy(void * restrict, void const * restrict, size_t)" is suspicious. > ><a name='def947'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def947'>[#def947]</a> >qemu-kvm-1.2.0/hw/qxl.c:954: <b>suspicious_sizeof</b>: Passing argument "caps" of type "uint8_t *" and argument "8UL /* sizeof (caps) */" to function "memcpy(void * restrict, void const * restrict, size_t)" is suspicious. > ><a name='def948'/><b>Error: <span style='background: #C0FF00;'>STRING_NULL</span> (CWE-170):</b> <a href ='#def948'>[#def948]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:781: <b>string_null_argument</b>: Function "readlink(char const * restrict, char * restrict, size_t)" does not terminate string "*driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:782: <b>cond_false</b>: Condition "r <= 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:782: <b>cond_false</b>: Condition "r >= 4096UL /* sizeof (driver) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:784: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:786: <b>string_null</b>: Passing unterminated string "driver" to "strrchr(char const *, int)", which expects a null-terminated string. > ><a name='def949'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def949'>[#def949]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1104: <b>cond_false</b>: Condition "sockfd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1107: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1108: <b>fixed_size_dest</b>: You might overrun the 108 byte fixed-size string "helper.sun_path" by copying "path" without checking the length.</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1108: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. > ><a name='def950'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def950'>[#def950]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_true</b>: Condition "modrm.rm", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6219: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> >qemu-kvm-1.2.0/i386-dis.c:6220: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[0]" by copying "names[0]" without checking the length. > ><a name='def951'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def951'>[#def951]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_false</b>: Condition "modrm.rm", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6223: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6226: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6229: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6233: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6234: <b>cond_true</b>: Condition "address_mode != mode_32bit", taking true branch</span> >qemu-kvm-1.2.0/i386-dis.c:6238: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[0]" by copying "op1_names[0]" without checking the length. > ><a name='def952'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def952'>[#def952]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_true</b>: Condition "modrm.rm", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6219: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6221: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6242: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> >qemu-kvm-1.2.0/i386-dis.c:6244: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[1]" by copying "names[1]" without checking the length. > ><a name='def953'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def953'>[#def953]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_false</b>: Condition "modrm.rm", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6223: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6226: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6229: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6233: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6234: <b>cond_true</b>: Condition "address_mode != mode_32bit", taking true branch</span> >qemu-kvm-1.2.0/i386-dis.c:6239: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[2]" by copying "names[2]" without checking the length. > ><a name='def954'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def954'>[#def954]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6260: <b>switch</b>: Switch case value "216"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6262: <b>switch_case</b>: Reached case "216"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6264: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6289: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6293: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6296: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6300: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6302: <b>switch</b>: Switch case value "223"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6304: <b>switch_case</b>: Reached case "223"</span> >qemu-kvm-1.2.0/i386-dis.c:6305: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[1]" by copying "names32[1]" without checking the length. > ><a name='def955'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def955'>[#def955]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1293: <b>cond_false</b>: Condition "dev->fd != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1295: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1298: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1300: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1305: <b>fixed_size_dest</b>: You might overrun the 16 byte fixed-size string "dev->port" by copying "port" without checking the length.</span> >qemu-kvm-1.2.0/hw/usb/host-linux.c:1305: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. > ><a name='def956'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def956'>[#def956]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "122"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6913: <b>switch_case</b>: Reached case "122"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6918: <b>cond_false</b>: Condition "!(buf = lock_user(1, arg1, 390L /* sizeof (*buf) */, 0))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6919: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6921: <b>cond_true</b>: Condition "!is_error(ret)", taking true branch</span> >qemu-kvm-1.2.0/linux-user/syscall.c:6924: <b>fixed_size_dest</b>: You might overrun the 65 byte fixed-size string "buf->machine" by copying the return value of "cpu_to_uname_machine(void *)" without checking the length. > ><a name='def957'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def957'>[#def957]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "122"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6913: <b>switch_case</b>: Reached case "122"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6918: <b>cond_false</b>: Condition "!(buf = lock_user(1, arg1, 390L /* sizeof (*buf) */, 0))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6919: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6921: <b>cond_true</b>: Condition "!is_error(ret)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6926: <b>cond_true</b>: Condition "qemu_uname_release", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6926: <b>cond_true</b>: Condition "*qemu_uname_release", taking true branch</span> >qemu-kvm-1.2.0/linux-user/syscall.c:6927: <b>fixed_size_dest</b>: You might overrun the 65 byte fixed-size string "buf->release" by copying "qemu_uname_release" without checking the length. > ><a name='def958'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def958'>[#def958]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1934: <b>cond_true</b>: Condition "*s == 'p'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'm'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'M'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'z'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1949: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1953: <b>cond_false</b>: Condition "opcodep->match != 3583U /* 255 + 13 * 256 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1954: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1958: <b>cond_true</b>: Condition "opcodep->name[0] == 'j'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1960: <b>cond_true</b>: Condition "__coverity_strncmp(opcodep->name, "jsr", 3UL /* sizeof ("jsr") - 1 */) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1962: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1965: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'P'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2500: <b>switch_case</b>: Reached case "'P'"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2505: <b>cond_false</b>: Condition "sregp->name == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2509: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2510: <b>cond_false</b>: Condition "with_reg_prefix", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2511: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/cris-dis.c:2512: <b>fixed_size_dest</b>: You might overrun the 62 byte fixed-size string "tp" by copying "sregp->name" without checking the length. > ><a name='def959'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def959'>[#def959]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:713: <b>fixed_size_dest</b>: You might overrun the 108 byte fixed-size string "proxy.sun_path" by copying "path" without checking the length.</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:713: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. > ><a name='def960'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def960'>[#def960]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:448: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:449: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:451: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "hdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:452: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:453: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:457: <b>cond_false</b>: Condition "hdr->ih_magic != 654645590", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:461: <b>cond_false</b>: Condition "hdr->ih_type != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:464: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:466: <b>switch</b>: Switch case value "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:467: <b>switch_case</b>: Reached case "0"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:469: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:475: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:478: <b>cond_true</b>: Condition "is_linux", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:479: <b>cond_true</b>: Condition "hdr->ih_os == 5", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:480: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:482: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:488: <b>tainted_data</b>: Passing tainted variable "hdr->ih_size" to a tainted sink. > ><a name='def961'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def961'>[#def961]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:194: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "e".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:219: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:220: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>tainted_data</b>: Passing tainted variable "e.a_data" to a tainted sink.</span> >qemu-kvm-1.2.0/hw/loader.c:97:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "nbytes" to tainted data sink "read(int, void *, size_t)". > ><a name='def962'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def962'>[#def962]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:194: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "e".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:218: <b>tainted_data</b>: Passing tainted variable "e.a_text" to a tainted sink.</span> >qemu-kvm-1.2.0/hw/loader.c:97:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "nbytes" to tainted data sink "read(int, void *, size_t)". > ><a name='def963'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def963'>[#def963]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:124: <b>cond_false</b>: Condition "!syms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:125: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:130: <b>cond_false</b>: Condition "i < nsyms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:149: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:150: <b>cond_false</b>: Condition "nsyms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:159: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:165: <b>cond_false</b>: Condition "symtab->sh_link >= ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:166: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:167: <b>var_assign_var</b>: Assigning: "strtab" = "shdr_table + symtab->sh_link". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:169: <b>tainted_data</b>: Passing tainted variable "strtab->sh_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def964'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def964'>[#def964]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>tainted_data_transitive</b>: Call to function "find_section32(struct elf32_shdr *, int, int)" with tainted argument "shdr_table" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:56:5: <b>cond_true</b>: Condition "i < n", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:57:9: <b>cond_true</b>: Condition "(shdr_table + i).sh_type == type", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:58:13: <b>return_tainted_data</b>: Returning tainted variable "shdr_table + i".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>var_assign</b>: Assigning: "symtab" = "find_section32(struct elf32_shdr *, int, int)", which taints "symtab".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:123: <b>tainted_data</b>: Passing tainted variable "symtab->sh_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def965'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def965'>[#def965]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:237: <b>var_assign_var</b>: Assigning: "size" = "ehdr.e_phnum * 32UL". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data</b>: Passing tainted variable "size" to a tainted sink. > ><a name='def966'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def966'>[#def966]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:235: <b>tainted_data</b>: Passing tainted variable "ehdr.e_shnum" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "40UL * ehdr->e_shnum" to tainted data sink "load_at(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def967'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def967'>[#def967]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> >qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. > ><a name='def968'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def968'>[#def968]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. > ><a name='def969'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def969'>[#def969]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def970'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def970'>[#def970]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def971'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def971'>[#def971]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_false</b>: Condition "addr < low", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:288: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def972'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def972'>[#def972]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def973'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def973'>[#def973]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def974'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def974'>[#def974]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def975'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def975'>[#def975]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def976'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def976'>[#def976]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def977'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def977'>[#def977]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def978'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def978'>[#def978]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def979'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def979'>[#def979]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def980'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def980'>[#def980]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:124: <b>cond_false</b>: Condition "!syms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:125: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:130: <b>cond_false</b>: Condition "i < nsyms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:149: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:150: <b>cond_false</b>: Condition "nsyms", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:159: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:165: <b>cond_false</b>: Condition "symtab->sh_link >= ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:166: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:167: <b>var_assign_var</b>: Assigning: "strtab" = "shdr_table + symtab->sh_link". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:169: <b>tainted_data</b>: Passing tainted variable "strtab->sh_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def981'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def981'>[#def981]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>tainted_data_transitive</b>: Call to function "find_section64(struct elf64_shdr *, int, int)" with tainted argument "shdr_table" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:56:5: <b>cond_true</b>: Condition "i < n", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:57:9: <b>cond_true</b>: Condition "(shdr_table + i).sh_type == type", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:58:13: <b>return_tainted_data</b>: Returning tainted variable "shdr_table + i".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>var_assign</b>: Assigning: "symtab" = "find_section64(struct elf64_shdr *, int, int)", which taints "symtab".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:123: <b>tainted_data</b>: Passing tainted variable "symtab->sh_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def982'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def982'>[#def982]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:237: <b>var_assign_var</b>: Assigning: "size" = "ehdr.e_phnum * 56UL". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data</b>: Passing tainted variable "size" to a tainted sink. > ><a name='def983'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def983'>[#def983]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:235: <b>tainted_data</b>: Passing tainted variable "ehdr.e_shnum" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "64UL * ehdr->e_shnum" to tainted data sink "load_at(int, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". > ><a name='def984'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def984'>[#def984]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> >qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. > ><a name='def985'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def985'>[#def985]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. > ><a name='def986'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def986'>[#def986]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def987'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def987'>[#def987]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def988'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def988'>[#def988]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_false</b>: Condition "addr < low", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:288: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def989'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def989'>[#def989]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def990'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def990'>[#def990]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def991'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def991'>[#def991]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def992'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def992'>[#def992]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def993'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def993'>[#def993]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def994'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def994'>[#def994]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def995'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def995'>[#def995]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> >qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def996'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def996'>[#def996]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. > ><a name='def997'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def997'>[#def997]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1914: <b>var_assign_var</b>: Assigning: "i" = "(shdr + str_idx).sh_size". Both are now tainted.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1915: <b>tainted_data</b>: Passing tainted variable "i" to a tainted sink. > ><a name='def998'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def998'>[#def998]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1916: <b>cond_false</b>: Condition "!strings", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1916: <b>cond_false</b>: Condition "pread(fd, strings, i, (shdr + str_idx).sh_offset) != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1918: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1920: <b>var_assign_var</b>: Assigning: "i" = "(shdr + sym_idx).sh_size". Both are now tainted.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1921: <b>tainted_data</b>: Passing tainted variable "i" to a tainted sink. > ><a name='def999'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def999'>[#def999]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1899: <b>var_assign_var</b>: Assigning: "str_idx" = "(shdr + i).sh_link". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1914: <b>tainted_data</b>: Using tainted variable "str_idx" as an index to pointer "shdr". > ><a name='def1000'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1000'>[#def1000]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "146"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7197:10: <b>switch_case</b>: Reached case "146"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7199:23: <b>parm_assign_alias</b>: Assigning: "count" = "arg3", which taints "count".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7203:13: <b>cond_false</b>: Condition "lock_iovec(0, vec, arg2, count, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7204:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:7205:13: <b>data_index</b>: Passing tainted variable "count" to a tainted data index sink. > ><a name='def1001'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1001'>[#def1001]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "57"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5700:10: <b>switch_case</b>: Reached case "57"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:5701:9: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg2" to tainted data sink "setpgid(__pid_t, __pid_t)". > ><a name='def1002'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1002'>[#def1002]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "37"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5579:10: <b>switch_case</b>: Reached case "37"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5580:9: <b>data_index</b>: Passing tainted variable "arg2" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> >qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". > ><a name='def1003'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1003'>[#def1003]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "146"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7197:10: <b>switch_case</b>: Reached case "146"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7199:23: <b>parm_assign_alias</b>: Assigning: "count" = "arg3", which taints "count".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7203:13: <b>cond_false</b>: Condition "lock_iovec(0, vec, arg2, count, 1) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7204:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:7205:13: <b>data_index</b>: Passing tainted variable "count" to a tainted data index sink. > ><a name='def1004'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1004'>[#def1004]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[1]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "57"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5700:10: <b>switch_case</b>: Reached case "57"</span> >qemu-kvm-1.2.0/linux-user/syscall.c:5701:9: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg1" to tainted data sink "setpgid(__pid_t, __pid_t)". > ><a name='def1005'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1005'>[#def1005]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "37"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5579:10: <b>switch_case</b>: Reached case "37"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5580:9: <b>data_index</b>: Passing tainted variable "arg2" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> >qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". > ><a name='def1006'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1006'>[#def1006]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5153:10: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5154:9: <b>cond_false</b>: Condition "arg3 == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5156:14: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5157:13: <b>cond_false</b>: Condition "!(p = lock_user(1, arg2, arg3, 0))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5158:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/syscall.c:5159:13: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg3" to tainted data sink "read(int, void *, size_t)". > ><a name='def1007'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1007'>[#def1007]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "265"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8463:10: <b>switch_case</b>: Reached case "265"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8464:2: <b>data_index</b>: Passing tainted variable "arg3" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> >qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". > ><a name='def1008'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1008'>[#def1008]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "!f", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "!(kernel_size = get_file_size(f))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_true</b>: Condition "8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>tainted_data_argument</b>: Calling function "fread(void * restrict, size_t, size_t, FILE * restrict)" taints argument "header".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_true</b>: Condition "8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "fread(header, 1, ((8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size) ? 8192UL /* sizeof (header) / sizeof (header[0]) */ : kernel_size), f) != ((8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size) ? 8192UL /* sizeof (header) / sizeof (header[0]) */ : kernel_size)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:690: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:696: <b>cond_true</b>: Condition "ldl_le_p(&header[514]) == 1400005704", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:697: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:705: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:707: <b>cond_true</b>: Condition "protocol < 512", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:712: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:722: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:735: <b>cond_false</b>: Condition "protocol >= 515", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:738: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:740: <b>cond_true</b>: Condition "initrd_max >= max_ram_size - 65536", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:745: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:749: <b>cond_false</b>: Condition "protocol >= 514", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:751: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:758: <b>cond_true</b>: Condition "vmode", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:762: <b>cond_true</b>: Condition "!__coverity_strncmp(vmode, "normal", 6)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:764: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:770: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:778: <b>cond_false</b>: Condition "protocol >= 512", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:779: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:782: <b>cond_false</b>: Condition "protocol >= 513", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:785: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:788: <b>cond_false</b>: Condition "initrd_filename", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:812: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:815: <b>lower_bounds</b>: Casting narrower unsigned "header[497]" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:815: <b>var_assign_var</b>: Assigning: "setup_size" = "header[497]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:816: <b>cond_false</b>: Condition "setup_size == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:817: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:818: <b>var_assign_var</b>: Assigning: "setup_size" = "(setup_size + 1) * 512". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:819: <b>var_assign_var</b>: Compound assignment involving tainted variable "setup_size" to variable "kernel_size" taints "kernel_size".</span> >qemu-kvm-1.2.0/hw/pc.c:824: <b>tainted_data</b>: Passing tainted variable "setup_size" to a tainted sink. > ><a name='def1009'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1009'>[#def1009]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:775: <b>cond_false</b>: Condition "!new_brk", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:778: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:779: <b>cond_false</b>: Condition "new_brk < target_original_brk", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:783: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:787: <b>cond_false</b>: Condition "new_brk <= brk_page", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:796: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(brk_page, new_alloc_size, 3, 34, 0, 0U)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>var_assign</b>: Assigning: "mapped_addr" = "get_errno(abi_long)", which taints "mapped_addr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:809: <b>cond_false</b>: Condition "mapped_addr == brk_page", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:824: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:824: <b>cond_true</b>: Condition "mapped_addr != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:828: <b>tainted_data</b>: Passing tainted variable "mapped_addr" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:643:5: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:644:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:646:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:647:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:653:5: <b>cond_true</b>: Condition "start > real_start", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:653:5: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "start" by "start > real_start".</span> >qemu-kvm-1.2.0/linux-user/mmap.c:656:9: <b>a_loop_bound</b>: Using tainted variable "start" as a loop boundary. > ><a name='def1010'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1010'>[#def1010]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1011'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1011'>[#def1011]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1012'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1012'>[#def1012]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1013'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1013'>[#def1013]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1014'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1014'>[#def1014]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1015'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1015'>[#def1015]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1016'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1016'>[#def1016]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1017'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1017'>[#def1017]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1018'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1018'>[#def1018]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1019'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1019'>[#def1019]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1020'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1020'>[#def1020]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1021'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1021'>[#def1021]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1022'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1022'>[#def1022]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1023'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1023'>[#def1023]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1024'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1024'>[#def1024]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1025'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1025'>[#def1025]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1026'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1026'>[#def1026]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1027'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1027'>[#def1027]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1028'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1028'>[#def1028]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1029'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1029'>[#def1029]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1030'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1030'>[#def1030]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1031'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1031'>[#def1031]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1032'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1032'>[#def1032]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1033'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1033'>[#def1033]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1034'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1034'>[#def1034]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1035'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1035'>[#def1035]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1036'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1036'>[#def1036]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1037'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1037'>[#def1037]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1038'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1038'>[#def1038]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1039'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1039'>[#def1039]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1040'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1040'>[#def1040]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1041'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1041'>[#def1041]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1042'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1042'>[#def1042]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1043'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1043'>[#def1043]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1044'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1044'>[#def1044]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1045'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1045'>[#def1045]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". > ><a name='def1046'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1046'>[#def1046]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1047'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1047'>[#def1047]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1048'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1048'>[#def1048]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1049'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1049'>[#def1049]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> >qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". > ><a name='def1050'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1050'>[#def1050]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 1, 0)" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1319: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". > ><a name='def1051'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1051'>[#def1051]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 16, 0)" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1388: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". > ><a name='def1052'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1052'>[#def1052]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 7, 0)" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1463: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". > ><a name='def1053'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1053'>[#def1053]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 3, 0)" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1482: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1485: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1487: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1489: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". > ><a name='def1054'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1054'>[#def1054]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1482: <b>cond_true</b>: Condition "pos", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1485: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1487: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 9, pos)" to wider signed type int effectively tests its lower bound.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>cond_true</b>: Condition "pos = pci_find_cap_offset(pci_dev, 9, pos)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1501: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1503: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1505: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". > ><a name='def1055'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1055'>[#def1055]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "*__errno_location() == 16", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "first", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:980: <b>tainted_data_return</b>: Function "usb_linux_get_num_interfaces(USBHostDevice *)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:535:5: <b>tainted_data_argument</b>: Function "usb_host_read_file(char *, size_t, char const *, char const *)" taints argument "line".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1626:5: <b>cond_true</b>: Condition "f", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1627:9: <b>tainted_data_argument</b>: Calling function "fgets(char * restrict, int, FILE * restrict)" taints parameter "*line".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:535:5: <b>cond_false</b>: Condition "!usb_host_read_file(line, 1024UL /* sizeof (line) */, "bNumInterfaces", device_name)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:538:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:539:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "line" taints "num_interfaces".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:539:5: <b>cond_false</b>: Condition "sscanf(line, "%d", &num_interfaces) != 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:541:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:542:5: <b>return_tainted_data</b>: Returning tainted variable "num_interfaces".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:980: <b>var_assign</b>: Assigning: "count" = "usb_linux_get_num_interfaces(USBHostDevice *)", which taints "count".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:981: <b>cond_true</b>: Condition "count > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:981: <b>lower_bounds</b>: Checking lower bounds of signed scalar "count" by "count > 0".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:983: <b>tainted_data</b>: Passing tainted variable "count" to a tainted sink.</span> >qemu-kvm-1.2.0/hw/usb/host-linux.c:515:5: <b>a_loop_bound</b>: Using tainted variable "nb_interfaces" as a loop boundary. > ><a name='def1056'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1056'>[#def1056]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>cond_true</b>: Condition "addr < real_end", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:165: <b>cond_true</b>: Condition "addr < start", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:167: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>cond_false</b>: Condition "addr < real_end", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:167: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:169: <b>cond_true</b>: Condition "prot1 == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:173: <b>cond_false</b>: Condition "p == (void *)0xffffffffffffffff", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:174: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:180: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:183: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:183: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:185: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:188: <b>cond_true</b>: Condition "!(prot1 & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:192: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> >qemu-kvm-1.2.0/linux-user/mmap.c:192: <b>tainted_data</b>: Passing tainted variable "end - start" to a tainted sink. > ><a name='def1057'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1057'>[#def1057]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:584: <b>tainted_data</b>: Passing tainted variable "start + len" to a tainted sink.</span> >qemu-kvm-1.2.0/exec.c:1076:5: <b>a_loop_bound</b>: Using tainted variable "end" as a loop boundary. > ><a name='def1058'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1058'>[#def1058]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. > ><a name='def1059'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1059'>[#def1059]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1769: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. > ><a name='def1060'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1060'>[#def1060]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_false</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>else_branch</b>: Reached else branch</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1772: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. > ><a name='def1061'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1061'>[#def1061]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1721: <b>tainted_data</b>: Passing tainted variable "eppnt->p_offset - vaddr_po" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:461:12: <b>var_assign_alias</b>: Assigning: "len" = "sb.st_size - offset". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "pread(int, void *, size_t, __off64_t)". > ><a name='def1062'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1062'>[#def1062]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1777: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1778: <b>tainted_data</b>: Using tainted variable "eppnt->p_filesz - 1U" as an index to pointer "interp_name". > ><a name='def1063'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1063'>[#def1063]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1817: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1819: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1821: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "bprm_buf".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1822: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1824: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1825: <b>cond_true</b>: Condition "retval < 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1829: <b>tainted_data</b>: Passing tainted variable "bprm_buf" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1603:25: <b>var_assign_parm</b>: Assigning: "ehdr" = "bprm_buf". "ehdr" is now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611:5: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615:5: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620:5: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1629:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "ehdr->e_phnum" to tainted data sink "bswap_phdr(struct elf32_phdr *, int)".</span> >qemu-kvm-1.2.0/linux-user/elfload.c:1084:5: <b>a_loop_bound</b>: Using tainted variable "phnum" as a loop boundary. > ><a name='def1064'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1064'>[#def1064]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:600: <b>cond_false</b>: Condition "reader_status == VREADER_OK", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:608: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:615: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:653: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:654: <b>cond_true</b>: Condition "rv >= 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:594: <b>var_assign_var</b>: Assigning: "dwSendLength" = "mhHeader.length". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:597: <b>tainted_data</b>: Passing tainted variable "dwSendLength" to a tainted sink.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:199:5: <b>cond_false</b>: Condition "card == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:201:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:203:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "send_buf_len" to tainted data sink "vcard_apdu_new(unsigned char *, int, vcard_7816_status_t *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:334:5: <b>cond_false</b>: Condition "len < 4", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:337:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:334:5: <b>lower_bounds</b>: Checking lower bounds of signed scalar "len" by "len < 4".</span> >qemu-kvm-1.2.0/libcacard/card_7816.c:341:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def1065'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1065'>[#def1065]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> >qemu-kvm-1.2.0/libcacard/vscclient.c:575: <b>tainted_data</b>: Passing tainted variable "mhHeader.length" to a tainted sink. > ><a name='def1066'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1066'>[#def1066]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:591: <b>tainted_data</b>: Passing tainted variable "mhHeader.length" to a tainted sink.</span> >qemu-kvm-1.2.0/libcacard/vscclient.c:35:5: <b>a_loop_bound</b>: Using tainted variable "nSize" as a loop boundary. > ><a name='def1067'/><b>Error: <span style='background: #C0FF00;'>TAINTED_STRING</span> (CWE-20):</b> <a href ='#def1067'>[#def1067]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string_return_content</b>: "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted string content.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_string_return_content</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted string content.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_string_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_string</b>: Returning tainted string "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6))", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_string</b>: Returning tainted string "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(env, n, env->dregs[1], env->dregs[2], env->dregs[3], env->dregs[4], env->dregs[5], env->aregs[0], 0, 0)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> >qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string</b>: Passing tainted string "env->dregs[1]" to "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which cannot accept tainted data. ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "8"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5224:10: <b>switch_case</b>: Reached case "8"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>tainted_data_transitive</b>: Call to function "lock_user_string(abi_ulong)" with tainted argument "arg1" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>tainted_data_transitive</b>: Calling function "lock_user(int, abi_ulong, long, int)" with tainted argument "guest_addr" results in tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_false</b>: Condition "!access_ok(type, guest_addr, len)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:421:5: <b>return_tainted_data</b>: Returning tainted variable "(void *)((unsigned long)(target_ulong)guest_addr + guest_base)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_tainted_data</b>: Returning tainted variable "lock_user(0, guest_addr, (long)(len + 1), 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>var_assign_var</b>: Assigning: "p" = "lock_user_string(arg1)". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>cond_false</b>: Condition "!(p = lock_user_string(arg1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5226:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5227:9: <b>tainted_string_sink_content_lv_call</b>: Passing tainted string "p" to "creat(char const *, mode_t)", which depends on its content.</span> > ><a name='def1068'/><b>Error: <span style='background: #C0FF00;'>TAINTED_STRING</span> (CWE-20):</b> <a href ='#def1068'>[#def1068]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string_return_content</b>: "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted string content.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_string_return_content</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted string content.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_string_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_string</b>: Returning tainted string "start".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6))", which taints "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_string</b>: Returning tainted string "ret".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(env, n, env->dregs[1], env->dregs[2], env->dregs[3], env->dregs[4], env->dregs[5], env->aregs[0], 0, 0)", which taints "env->dregs[0]".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> >qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string</b>: Passing tainted string "env->dregs[2]" to "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which cannot accept tainted data. ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "38"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5582:10: <b>switch_case</b>: Reached case "38"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5586:13: <b>tainted_data_transitive</b>: Call to function "lock_user_string(abi_ulong)" with tainted argument "arg2" returns tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>tainted_data_transitive</b>: Calling function "lock_user(int, abi_ulong, long, int)" with tainted argument "guest_addr" results in tainted data.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_false</b>: Condition "!access_ok(type, guest_addr, len)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:421:5: <b>return_tainted_data</b>: Returning tainted variable "(void *)((unsigned long)(target_ulong)guest_addr + guest_base)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_tainted_data</b>: Returning tainted variable "lock_user(0, guest_addr, (long)(len + 1), 1)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5586:13: <b>var_assign_var</b>: Assigning: "p2" = "lock_user_string(arg2)". Both are now tainted.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5587:13: <b>cond_false</b>: Condition "!p", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5587:13: <b>cond_false</b>: Condition "!p2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5590:17: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5590:17: <b>tainted_string_sink_content_lv_call</b>: Passing tainted string "p2" to "rename(char const *, char const *)", which depends on its content.</span> > ><a name='def1069'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1069'>[#def1069]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:857: <b>cond_true</b>: Condition "ctx->export_flags & 0x20", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:858: <b>fs_check_call</b>: Calling function "lstat(char const *, struct stat *)" to perform check on "rpath(ctx, path, buffer)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:859: <b>cond_false</b>: Condition "err", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:861: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:866: <b>cond_true</b>: Condition "(stbuf.st_mode & 61440) == 16384", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:869: <b>cond_true</b>: Condition "err < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:869: <b>cond_false</b>: Condition "*__errno_location() != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:875: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:882: <b>cond_true</b>: Condition "err < 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:882: <b>cond_false</b>: Condition "*__errno_location() != 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:888: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:890: <b>toctou</b>: Calling function "remove(char const *)" that uses "rpath(ctx, path, buffer)" after a check function. This can cause a time-of-check, time-of-use race condition. > ><a name='def1070'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1070'>[#def1070]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:119: <b>cond_true</b>: Condition "dns_addr.s_addr != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:121: <b>cond_false</b>: Condition "curtime - dns_addr_time < 1000", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:124: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:126: <b>fs_check_call</b>: Calling function "stat(char const *, struct stat *)" to perform check on ""/etc/resolv.conf"".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:126: <b>cond_false</b>: Condition "stat("/etc/resolv.conf", &dns_addr_stat) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:127: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_dev == old_stat.st_dev", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_ino == old_stat.st_ino", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_size == old_stat.st_size", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_false</b>: Condition "dns_addr_stat.st_mtim.tv_sec == old_stat.st_mtim.tv_sec", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:134: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/slirp/slirp.c:137: <b>toctou</b>: Calling function "fopen(char const * restrict, char const * restrict)" that uses ""/etc/resolv.conf"" after a check function. This can cause a time-of-check, time-of-use race condition. > ><a name='def1071'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1071'>[#def1071]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1873: <b>cond_false</b>: Condition "dev->dev.romfile", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1873: <b>cond_false</b>: Condition "!dev->dev.rom_bar", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1875: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1882: <b>cond_false</b>: Condition "stat(rom_file, &st)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1884: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1886: <b>fs_check_call</b>: Calling function "access(char const *, int)" to perform check on "rom_file".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1886: <b>cond_false</b>: Condition "access(rom_file, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1890: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1893: <b>toctou</b>: Calling function "fopen(char const * restrict, char const * restrict)" that uses "rom_file" after a check function. This can cause a time-of-check, time-of-use race condition. > ><a name='def1072'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1072'>[#def1072]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:242: <b>fs_check_call</b>: Calling function "stat(char const *, struct stat *)" to perform check on "path".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:249: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:249: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:255: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_false</b>: Condition "i < 2", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop_end</b>: Reached end of loop</span> >qemu-kvm-1.2.0/oslib-posix.c:258: <b>toctou</b>: Calling function "utimes(char const *, struct timeval const *)" that uses "path" after a check function. This can cause a time-of-check, time-of-use race condition. > ><a name='def1073'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1073'>[#def1073]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "112"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1006: <b>switch_case</b>: Reached case "112"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1007: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1008: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "110"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1009: <b>switch_case</b>: Reached case "110"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1011: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "102"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1012: <b>switch_case</b>: Reached case "102"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1014: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_true</b>: Condition "c == -1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1003: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_true</b>: Condition "sock_name == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_false</b>: Condition "rpath == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1037: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1039: <b>cond_false</b>: Condition "sock_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1043: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1045: <b>cond_false</b>: Condition "sock_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1051: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1053: <b>cond_false</b>: Condition "lstat(rpath, &stbuf) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1057: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1059: <b>cond_false</b>: Condition "!((stbuf.st_mode & 61440) == 16384)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1062: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1064: <b>cond_false</b>: Condition "is_daemon", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1070: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1073: <b>cond_false</b>: Condition "sock_name", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1078: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1083: <b>fs_check_call</b>: Calling function "statfs(char const *, struct statfs *)" to perform check on "rpath".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1084: <b>cond_true</b>: Condition "!retval", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1085: <b>switch</b>: Switch case value "61267L"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1086: <b>switch_case</b>: Reached case "61267L"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1091: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1092: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1096: <b>cond_false</b>: Condition "chdir("/") < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1099: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1100: <b>toctou</b>: Calling function "chroot(char const *)" that uses "rpath" after a check function. This can cause a time-of-check, time-of-use race condition. > ><a name='def1074'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1074'>[#def1074]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:344: <b>var_decl</b>: Declaring variable "cpkt" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:350: <b>cond_false</b>: Condition "len < 8UL /* sizeof (cpkt) */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:353: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:360: <b>cond_false</b>: Condition "cpkt.event == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:374: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:377: <b>cond_false</b>: Condition "!port", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:387: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:388: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:389: <b>cond_false</b>: Condition "!cpkt.value", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:393: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:401: <b>cond_true</b>: Condition "vsc->is_console", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:405: <b>cond_true</b>: Condition "port->name", taking true branch</span> >qemu-kvm-1.2.0/hw/virtio-serial-bus.c:412: <b>uninit_use_in_call</b>: Using uninitialized value "cpkt": field "cpkt"."id" is uninitialized when calling "memcpy(void * restrict, void const * restrict, size_t)". > ><a name='def1075'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1075'>[#def1075]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2753: <b>var_decl</b>: Declaring variable "info" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2764: <b>cond_false</b>: Condition "dumpsize.rlim_cur == 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2765: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2767: <b>cond_false</b>: Condition "core_dump_filename(ts, corefile, 4096UL /* sizeof (corefile) */) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2768: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2770: <b>cond_false</b>: Condition "(fd = open(corefile, 65 /* 1 | 0x40 */, 420 /* ((0x100 | 0x80) | (0x100 >> 3)) | ((0x100 >> 3) >> 3) */)) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2772: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2779: <b>cond_true</b>: Condition "(mm = vma_init()) == NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2780: <b>goto</b>: Jumping to label "out"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2879: <b>label</b>: Reached label "out"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.notes" when calling "free_note_info(struct elf_note_info *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2682:5: <b>read_parm_fld</b>: Reading a parameter field.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.prstatus" when calling "free_note_info(struct elf_note_info *)".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2680:5: <b>read_parm_fld</b>: Reading a parameter field.</span> >qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.psinfo" when calling "free_note_info(struct elf_note_info *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2681:5: <b>read_parm_fld</b>: Reading a parameter field.</span> > ><a name='def1076'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1076'>[#def1076]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:372: <b>var_decl</b>: Declaring variable "act" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:377: <b>cond_false</b>: Condition "core_dump_signal(target_sig)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:381: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:382: <b>cond_false</b>: Condition "core_dumped", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:391: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/linux-user/signal.c:401: <b>uninit_use_in_call</b>: Using uninitialized value "act.sa_flags" when calling "sigaction(int, struct sigaction const * restrict, struct sigaction * restrict)". > ><a name='def1077'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1077'>[#def1077]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1078: <b>var_decl</b>: Declaring variable "p" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1081: <b>cond_false</b>: Condition "!usb_enabled", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1082: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1086: <b>cond_false</b>: Condition "dev", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1087: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1096: <b>cond_true</b>: Condition "!__coverity_strcmp(devname, "bt")", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1097: <b>cond_true</b>: Condition "devname[2]", taking true branch</span> >qemu-kvm-1.2.0/vl.c:1097: <b>uninit_use_in_call</b>: Using uninitialized value "p" when calling "hci_init(char const *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:640:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1078'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1078'>[#def1078]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1017: <b>var_decl</b>: Declaring variable "qhdb" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1029: <b>cond_true</b>: Condition "is_valid(link)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1029: <b>cond_true</b>: Condition "cnt", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1030: <b>cond_false</b>: Condition "s->frame_bytes >= s->frame_bandwidth", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1035: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1036: <b>cond_true</b>: Condition "is_qh(link)", taking true branch</span> >qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1040: <b>uninit_use_in_call</b>: Using uninitialized element of array "qhdb.addr" when calling "qhdb_insert(QhDb *, uint32_t)". ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:965:5: <b>cond_true</b>: Condition "i < db->count", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:966:9: <b>read_parm_fld</b>: Reading a parameter field.</span> > ><a name='def1079'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1079'>[#def1079]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:350: <b>var_decl</b>: Declaring variable "saddr" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:361: <b>cond_false</b>: Condition "is_connected", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:385: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:389: <b>cond_false</b>: Condition "is_connected", taking false branch</span> >qemu-kvm-1.2.0/net/socket.c:392: <b>uninit_use</b>: Using uninitialized value "saddr.sin_port". > ><a name='def1080'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1080'>[#def1080]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:352: <b>var_decl</b>: Declaring variable "saddr_len" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:361: <b>cond_true</b>: Condition "is_connected", taking true branch</span> >qemu-kvm-1.2.0/net/socket.c:362: <b>uninit_use_in_call</b>: Using uninitialized value "saddr_len" when calling "getsockname(int, __SOCKADDR_ARG, socklen_t * restrict)". > ><a name='def1081'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1081'>[#def1081]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:648: <b>var_decl</b>: Declaring variable "raddr" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:650: <b>cond_false</b>: Condition "parse_host_port(&laddr, lhost) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:652: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:654: <b>cond_false</b>: Condition "parse_host_port(&raddr, rhost) < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:656: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:659: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:662: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:666: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:670: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:672: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:676: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:679: <b>cond_false</b>: Condition "!s", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:681: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/net/socket.c:683: <b>uninit_use</b>: Using uninitialized value "raddr": field "raddr"."sin_zero" is uninitialized. > ><a name='def1082'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1082'>[#def1082]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:303: <b>var_decl</b>: Declaring variable "request" without initializer.</span> >qemu-kvm-1.2.0/block/nbd.c:308: <b>uninit_use_in_call</b>: Using uninitialized value "request.handle" when calling "nbd_send_request(int, struct nbd_request *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:485:5: <b>read_parm_fld</b>: Reading a parameter field.</span> > ><a name='def1083'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1083'>[#def1083]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:216: <b>var_decl</b>: Declaring variable "tv_now" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:240: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> >qemu-kvm-1.2.0/oslib-posix.c:247: <b>uninit_use</b>: Using uninitialized value "tv_now.tv_sec". > ><a name='def1084'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1084'>[#def1084]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:216: <b>var_decl</b>: Declaring variable "tv_now" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:240: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> >qemu-kvm-1.2.0/oslib-posix.c:248: <b>uninit_use</b>: Using uninitialized value "tv_now.tv_usec". > ><a name='def1085'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1085'>[#def1085]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/iohandler.c:206: <b>var_decl</b>: Declaring variable "act" without initializer.</span> >qemu-kvm-1.2.0/iohandler.c:211: <b>uninit_use_in_call</b>: Using uninitialized value "act.sa_mask": field "act.sa_mask"."__val" is uninitialized when calling "sigaction(int, struct sigaction const * restrict, struct sigaction * restrict)". > ><a name='def1086'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1086'>[#def1086]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:424: <b>var_decl</b>: Declaring variable "ret" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:426: <b>cond_false</b>: Condition "slirp_instances.tqh_first == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:428: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:436: <b>cond_true</b>: Condition "slirp", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:440: <b>cond_true</b>: Condition "time_fasttimo", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:440: <b>cond_true</b>: Condition "curtime - time_fasttimo >= 2", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:444: <b>cond_true</b>: Condition "do_slowtimo", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:444: <b>cond_true</b>: Condition "curtime - last_slowtimo >= 499", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:453: <b>cond_true</b>: Condition "!select_error", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:457: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_true</b>: Condition "so->so_state & 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:466: <b>continue</b>: Continuing loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:568: <b>loop</b>: Looping back</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:457: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_false</b>: Condition "so->so_state & 1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_false</b>: Condition "so->s == -1", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:466: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:473: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:473: <b>cond_true</b>: Condition "(xfds->fds_bits[({...})] & (1L /* (__fd_mask)1 */ << so->s % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:474: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:491: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:496: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:496: <b>cond_true</b>: Condition "(writefds->fds_bits[({...})] & (1L /* (__fd_mask)1 */ << so->s % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:500: <b>cond_true</b>: Condition "so->so_state & 2", taking true branch</span> >qemu-kvm-1.2.0/slirp/slirp.c:504: <b>uninit_use_in_call</b>: Using uninitialized value "ret" when calling "send(int, void const *, size_t, int)". > ><a name='def1087'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1087'>[#def1087]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:64: <b>var_decl</b>: Declaring variable "mhHeader" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:68: <b>cond_true</b>: Condition "verbose > 10", taking true branch</span> >qemu-kvm-1.2.0/libcacard/vscclient.c:76: <b>uninit_use_in_call</b>: Using uninitialized value "mhHeader": field "mhHeader"."data" is uninitialized when calling "write(int, void const *, size_t)". > ><a name='def1088'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1088'>[#def1088]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:66: <b>var_decl</b>: Declaring variable "entry" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:68: <b>cond_true</b>: Condition "kernel_filename", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:68: <b>cond_false</b>: Condition "!qtest_enabled()", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:88: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/hw/openrisc_sim.c:90: <b>uninit_use</b>: Using uninitialized value "entry". > ><a name='def1089'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1089'>[#def1089]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "0U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:97: <b>switch_case</b>: Reached case "0U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:98: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_add(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3419:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1090'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1090'>[#def1090]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "4194304U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:114: <b>switch_case</b>: Reached case "4194304U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:116: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_div(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3530:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1091'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1091'>[#def1091]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "5242880U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:119: <b>switch_case</b>: Reached case "5242880U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:121: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_div(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3529:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1092'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1092'>[#def1092]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "1048576U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:101: <b>switch_case</b>: Reached case "1048576U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:103: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_mul(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3468:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1093'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1093'>[#def1093]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "8388608U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:134: <b>switch_case</b>: Reached case "8388608U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:135: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_rem(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3603:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1094'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1094'>[#def1094]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "3178496U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:173: <b>switch_case</b>: Reached case "3178496U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:175: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_round_to_int(float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3196:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1095'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1095'>[#def1095]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "4227072U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:178: <b>switch_case</b>: Reached case "4227072U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:179: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sqrt(float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3906:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1096'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1096'>[#def1096]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "2097152U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:106: <b>switch_case</b>: Reached case "2097152U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:107: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sub(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3442:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1097'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1097'>[#def1097]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "3145728U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:110: <b>switch_case</b>: Reached case "3145728U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:111: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sub(float64, float64, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3441:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1098'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1098'>[#def1098]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "32768U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:145: <b>switch_case</b>: Reached case "32768U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:146: <b>uninit_use</b>: Using uninitialized value "rFm". > ><a name='def1099'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1099'>[#def1099]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "0U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:95: <b>switch_case</b>: Reached case "0U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:96: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_add(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4662:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1100'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1100'>[#def1100]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "4194304U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:112: <b>switch_case</b>: Reached case "4194304U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:114: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_div(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4767:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1101'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1101'>[#def1101]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "5242880U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:117: <b>switch_case</b>: Reached case "5242880U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:119: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_div(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4770:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1102'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1102'>[#def1102]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "1048576U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:99: <b>switch_case</b>: Reached case "1048576U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:101: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_mul(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4707:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1103'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1103'>[#def1103]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "8388608U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:132: <b>switch_case</b>: Reached case "8388608U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:133: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_rem(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4847:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1104'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1104'>[#def1104]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "2097152U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:104: <b>switch_case</b>: Reached case "2097152U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:105: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_sub(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4683:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1105'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1105'>[#def1105]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "3145728U"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:108: <b>switch_case</b>: Reached case "3145728U"</span> >qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:109: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_sub(floatx80, floatx80, float_status *)". ><span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4684:5: <b>read_parm</b>: Reading a parameter value.</span> > ><a name='def1106'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1106'>[#def1106]</a> >qemu-kvm-1.2.0/hw/usb/hcd-musb.c:573: <b>unreachable</b>: This code cannot be reached: "switch (ttype){ > case 0: ...". > ><a name='def1107'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1107'>[#def1107]</a> >qemu-kvm-1.2.0/gdbstub.c:446: <b>unreachable</b>: Since the loop increment is unreachable, the loop body will never execute more than once. > ><a name='def1108'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1108'>[#def1108]</a> >qemu-kvm-1.2.0/hw/sd.c:343: <b>unreachable</b>: This code cannot be reached: "return sd_crc7(buffer, 5UL)...". > ><a name='def1109'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1109'>[#def1109]</a> >qemu-kvm-1.2.0/hw/ide/microdrive.c:212: <b>unreachable</b>: This code cannot be reached: "if (s->cycle)ret = s->io >>...". > ><a name='def1110'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1110'>[#def1110]</a> >qemu-kvm-1.2.0/hw/ide/microdrive.c:273: <b>unreachable</b>: This code cannot be reached: "if (s->cycle)ide_data_write...". > ><a name='def1111'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1111'>[#def1111]</a> >qemu-kvm-1.2.0/block/qed.c:679: <b>returned_pointer</b>: Pointer "cb.co" returned by "qemu_coroutine_self()" is never used. > ><a name='def1112'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1112'>[#def1112]</a> >qemu-kvm-1.2.0/block/qed.c:1395: <b>returned_pointer</b>: Pointer "cb.co" returned by "qemu_coroutine_self()" is never used. > ><a name='def1113'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1113'>[#def1113]</a> >qemu-kvm-1.2.0/json-parser.c:545: <b>returned_pointer</b>: Pointer "token" returned by "parser_context_pop_token(ctxt)" is never used. > ><a name='def1114'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1114'>[#def1114]</a> >qemu-kvm-1.2.0/linux-user/mmap.c:484: <b>returned_pointer</b>: Pointer "p" returned by "mmap((void *)((unsigned long)(target_ulong)start + guest_base), len, prot, flags | 0x10, fd, host_offset)" is never used. > ><a name='def1115'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1115'>[#def1115]</a> >qemu-kvm-1.2.0/linux-user/mmap.c:754: <b>returned_pointer</b>: Pointer "host_addr" returned by "mremap((void *)((unsigned long)(target_ulong)old_addr + guest_base), new_size, old_size, flags)" is never used. > ><a name='def1116'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1116'>[#def1116]</a> >qemu-kvm-1.2.0/json-parser.c:466: <b>returned_pointer</b>: Pointer "token" returned by "parser_context_pop_token(ctxt)" is never used. > ><a name='def1117'/><b>Error: <span style='background: #C0FF00;'>USE_AFTER_FREE</span> (CWE-416):</b> <a href ='#def1117'>[#def1117]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:141: <b>cond_false</b>: Condition "envlist == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:141: <b>cond_false</b>: Condition "env == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:142: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:145: <b>cond_false</b>: Condition "(eq_sign = __coverity_strchr(env, 61)) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:146: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:154: <b>alias</b>: Assigning: "entry" = "envlist->el_entries.lh_first". Now both point to the same storage.</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:154: <b>cond_true</b>: Condition "entry != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:156: <b>cond_true</b>: Condition "__coverity_strncmp(entry->ev_var, env, envname_len) == 0", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:157: <b>break</b>: Breaking from loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:158: <b>loop_end</b>: Reached end of loop</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:160: <b>cond_true</b>: Condition "entry != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:161: <b>cond_true</b>: Condition "entry->ev_link.le_next != NULL", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:163: <b>freed_arg</b>: "free(void *)" frees "entry".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:164: <b>if_fallthrough</b>: Falling through to end of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:166: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:168: <b>cond_false</b>: Condition "(entry = malloc(24UL /* sizeof (*entry) */)) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:169: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:170: <b>cond_false</b>: Condition "0", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:170: <b>cond_false</b>: Condition "(entry->ev_var = ((0 && (size_t)(void const *)(env + 1) - (size_t)(void const *)env == 1) ? ((char const *)env[0] == 0) ? (char *)calloc(1UL /* (size_t)1 */, 1UL /* (size_t)1 */) : ({...}) : __strdup(env))) == NULL", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:173: <b>if_end</b>: End of if statement</span> >qemu-kvm-1.2.0/envlist.c:174: <b>use_after_free</b>: Using freed pointer "envlist->el_entries.lh_first". > ><a name='def1118'/><b>Error: <span style='background: #C0FF00;'>USE_AFTER_FREE</span> (CWE-416):</b> <a href ='#def1118'>[#def1118]</a> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:183: <b>cond_false</b>: Condition "!wav->f", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:185: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:190: <b>cond_false</b>: Condition "fseek(wav->f, 4, 0)", taking false branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:194: <b>if_end</b>: End of if statement</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:195: <b>cond_true</b>: Condition "fwrite(rlen, 4, 1, wav->f) != 1", taking true branch</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:198: <b>goto</b>: Jumping to label "doclose"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:211: <b>label</b>: Reached label "doclose"</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:212: <b>freed_arg</b>: "fclose(FILE *)" frees "wav->f".</span> ><span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:212: <b>cond_true</b>: Condition "fclose(wav->f)", taking true branch</span> >qemu-kvm-1.2.0/audio/wavaudio.c:213: <b>pass_freed_arg</b>: Passing freed pointer "wav->f" as an argument to function "dolog(char const *, ...)". > ></pre> ><h2>Scan Properties</h2> ><table style='font-family: monospace;'> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>analyzer</td><td>coverity</td></tr> ><tr><td style='padding-right: 8px;'>analyzer-args</td><td>--wait-for-license --security --concurrency</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>analyzer-version</td><td>Coverity Static Analysis for C/C++ version 6.5.0 on Linux 2.6.32-279.el6.x86_64 x86_64\nInternal version numbers: 5cf350e73a3d7603cb5520c80316bfaded6febde p-carmel-push-12518.257</td></tr> ><tr><td style='padding-right: 8px;'>compilation-unit-count</td><td>2633</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>compilation-unit-ratio</td><td>99</td></tr> ><tr><td style='padding-right: 8px;'>host</td><td>cov01.lab.eng.brq.redhat.com</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>lines-processed</td><td>761013</td></tr> ><tr><td style='padding-right: 8px;'>mock-config</td><td>fedora-rawhide-xscan</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>project-name</td><td>qemu-1.2.0-25.fc19</td></tr> ><tr><td style='padding-right: 8px;'>time-created</td><td>2012-12-07 08:44:41</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>time-elapsed-analysis</td><td>00:24:49</td></tr> ><tr><td style='padding-right: 8px;'>time-finished</td><td>2012-12-07 09:41:35</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>tool</td><td>cov-mockbuild</td></tr> ><tr><td style='padding-right: 8px;'>tool-args</td><td>-i fedora-rawhide-xscan qemu-1.2.0-25.fc19.src.rpm --security --concurrency</td></tr> ><tr style='background-color: #EEE;'><td style='padding-right: 8px;'>tool-version</td><td>cov-mockbuild-0.20121127_91fc7f1-1.el6.noarch csdiff-0.20121113_49dc2ca-1.el6.x86_64</td></tr> ></table> ></body> ></html>
<?xml version='1.0' encoding='utf-8'?> <!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.1//EN' 'http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd'> <html xmlns='http://www.w3.org/1999/xhtml'> <head><title>qemu-1.2.0-25.fc19</title></head> <body> <h1>qemu-1.2.0-25.fc19</h1> <a href='qemu-1.2.0-25.fc19.err'>[Show plain-text results]</a> <h2>List of Defects</h2> <pre style='white-space: pre-wrap;'> <a name='def1'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def1'>[#def1]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1858: <b>cond_true</b>: Condition "nb_regs > nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1865: <b>cond_false</b>: Condition "call_stack_size > 128", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1866: <b>cond_false</b>: Condition "allocate_args", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1870: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1880: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1882: <b>cond_false</b>: Condition "ts->val_type == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1888: <b>cond_true</b>: Condition "ts->val_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1894: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1896: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_true</b>: Condition "i < nb_params", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1878: <b>cond_false</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1897: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1873: <b>cond_false</b>: Condition "i < nb_params", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1901: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1912: <b>cond_true</b>: Condition "ts->reg != reg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1912: <b>cond_true</b>: Condition "ts->reg != reg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_true</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1911: <b>cond_false</b>: Condition "ts->val_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1915: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1917: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1922: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_true</b>: Condition "i < nb_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1907: <b>cond_false</b>: Condition "arg != 18446744073709551615UL /* (TCGArg)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1924: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1905: <b>cond_false</b>: Condition "i < nb_regs", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1925: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1933: <b>cond_true</b>: Condition "ts->val_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1938: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1958: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_true</b>: Condition "i < nb_iargs + nb_oargs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1964: <b>cond_true</b>: Condition "(dead_args >> i) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1966: <b>cond_true</b>: Condition "!ts->fixed_reg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1967: <b>cond_true</b>: Condition "ts->val_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_true</b>: Condition "i < nb_iargs + nb_oargs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1964: <b>cond_true</b>: Condition "(dead_args >> i) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1966: <b>cond_false</b>: Condition "!ts->fixed_reg", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1970: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1962: <b>cond_false</b>: Condition "i < nb_iargs + nb_oargs", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1972: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_true</b>: Condition "reg < 16", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1976: <b>cond_true</b>: Condition "(tcg_target_call_clobber_regs >> reg) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_true</b>: Condition "reg < 16", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1976: <b>cond_true</b>: Condition "(tcg_target_call_clobber_regs >> reg) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1975: <b>cond_false</b>: Condition "reg < 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1979: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1983: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1987: <b>address_of</b>: Taking address with "&func_arg" yields a singleton pointer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/tcg.c:1987: <b>callee_ptr_arith</b>: Passing "&func_arg" to function "tcg_out_op(TCGContext *, TCGOpcode, TCGArg const *, int const *)" which uses it as an array. This might corrupt or misinterpret adjacent memory locations.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1504:5: <b>switch</b>: Switch case value "INDEX_op_movi_i32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1541:10: <b>switch_case</b>: Reached case "INDEX_op_movi_i32"</span> qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1542:9: <b>ptr_arith</b>: Performing pointer arithmetic on "args" in expression "args + 1". <a name='def2'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def2'>[#def2]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:657: <b>address_of</b>: Taking address with "&d->ram->release_ring" yields a singleton pointer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:657: <b>assign</b>: Assigning: "ring" = "&d->ram->release_ring".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:663: <b>cond_false</b>: Condition "ring->prod - ring->cons + 1 == ring->num_items", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:667: <b>cond_true</b>: Condition "!flush", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:667: <b>cond_false</b>: Condition "d->oom_running", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:670: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:671: <b>cond_true</b>: Condition "!flush", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:671: <b>cond_false</b>: Condition "d->num_free_res < 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:674: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:676: <b>cond_true</b>: Condition "ring->prod == ring->notify_on_prod", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:677: <b>cond_true</b>: Condition "notify", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:682: <b>cond_true</b>: Condition "notify", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:685: <b>assign</b>: Assigning: "start" = "ring".</span> qemu-kvm-1.2.0/hw/qxl.c:685: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. <a name='def3'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def3'>[#def3]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:588: <b>switch</b>: Switch case value "QXL_MODE_COMPAT"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:604: <b>switch_case</b>: Reached case "QXL_MODE_COMPAT"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:607: <b>address_of</b>: Taking address with "&qxl->ram->cmd_ring" yields a singleton pointer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:607: <b>assign</b>: Assigning: "ring" = "&qxl->ram->cmd_ring".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:608: <b>cond_false</b>: Condition "qxl->guest_bug", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:608: <b>cond_false</b>: Condition "ring->cons == ring->prod", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:610: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:611: <b>assign</b>: Assigning: "start" = "ring".</span> qemu-kvm-1.2.0/hw/qxl.c:611: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. <a name='def4'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def4'>[#def4]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:748: <b>switch</b>: Switch case value "QXL_MODE_COMPAT"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:749: <b>switch_case</b>: Reached case "QXL_MODE_COMPAT"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:752: <b>address_of</b>: Taking address with "&qxl->ram->cursor_ring" yields a singleton pointer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:752: <b>assign</b>: Assigning: "ring" = "&qxl->ram->cursor_ring".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:753: <b>cond_false</b>: Condition "ring->cons == ring->prod", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:755: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:756: <b>assign</b>: Assigning: "start" = "ring".</span> qemu-kvm-1.2.0/hw/qxl.c:756: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. <a name='def5'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def5'>[#def5]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:703: <b>cond_false</b>: Condition "ext.group_id == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:713: <b>address_of</b>: Taking address with "&qxl->ram->release_ring" yields a singleton pointer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:713: <b>assign</b>: Assigning: "ring" = "&qxl->ram->release_ring".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:714: <b>assign</b>: Assigning: "start" = "ring".</span> qemu-kvm-1.2.0/hw/qxl.c:714: <b>ptr_arith</b>: Using "ring" as an array. This might corrupt or misinterpret adjacent memory locations. <a name='def6'/><b>Error: <span style='background: #C0FF00;'>ARRAY_VS_SINGLETON</span> (CWE-119):</b> <a href ='#def6'>[#def6]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:392: <b>address_of</b>: Taking address with "&d->ram->release_ring" yields a singleton pointer.</span> qemu-kvm-1.2.0/hw/qxl.c:392: <b>ptr_arith</b>: Using "&d->ram->release_ring" as an array. This might corrupt or misinterpret adjacent memory locations. <a name='def7'/><b>Error: <span style='background: #C0FF00;'>ATOMICITY</span> (CWE-662):</b> <a href ='#def7'>[#def7]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:296: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:298: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:300: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:303: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:304: <b>cond_false</b>: Condition "pa->done", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:306: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:308: <b>cond_true</b>: Condition "pa->dead > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:309: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:315: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:317: <b>cond_true</b>: Condition "ta > tb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:296: <b>lock</b>: Locking "pa->pt.mutex".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:318: <b>def</b>: Assigning data that might be protected by the lock to "wpos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:320: <b>unlock</b>: Unlocking "pa->pt.mutex". "wpos" might now be unreliable because other threads can now change the data that it depends on.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:320: <b>cond_false</b>: Condition "audio_pt_unlock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:322: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:324: <b>cond_false</b>: Condition "to_grab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:338: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:340: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:342: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:340: <b>lockagain</b>: Locking "pa->pt.mutex" again.</span> qemu-kvm-1.2.0/audio/paaudio.c:344: <b>use</b>: Using an unreliable value of "wpos" inside the second locked section. If the data that "wpos" depends on was changed by another thread, this use might be incorrect. <a name='def8'/><b>Error: <span style='background: #C0FF00;'>ATOMICITY</span> (CWE-662):</b> <a href ='#def8'>[#def8]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:204: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:208: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:211: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:212: <b>cond_false</b>: Condition "pa->done", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:214: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:216: <b>cond_true</b>: Condition "pa->live > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:217: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:223: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:225: <b>cond_true</b>: Condition "ta > tb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:204: <b>lock</b>: Locking "pa->pt.mutex".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:226: <b>def</b>: Assigning data that might be protected by the lock to "rpos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:228: <b>unlock</b>: Unlocking "pa->pt.mutex". "rpos" might now be unreliable because other threads can now change the data that it depends on.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:228: <b>cond_false</b>: Condition "audio_pt_unlock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:230: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:232: <b>cond_false</b>: Condition "to_mix", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:247: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:249: <b>cond_false</b>: Condition "audio_pt_lock(&pa->pt, <anonymous>)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:251: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/paaudio.c:249: <b>lockagain</b>: Locking "pa->pt.mutex" again.</span> qemu-kvm-1.2.0/audio/paaudio.c:253: <b>use</b>: Using an unreliable value of "rpos" inside the second locked section. If the data that "rpos" depends on was changed by another thread, this use might be incorrect. <a name='def9'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def9'>[#def9]</a> qemu-kvm-1.2.0/trace.h:1116: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def10'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def10'>[#def10]</a> qemu-kvm-1.2.0/trace.h:1116: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def11'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def11'>[#def11]</a> qemu-kvm-1.2.0/trace.h:1128: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def12'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def12'>[#def12]</a> qemu-kvm-1.2.0/trace.h:1128: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def13'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def13'>[#def13]</a> qemu-kvm-1.2.0/trace.h:1119: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def14'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def14'>[#def14]</a> qemu-kvm-1.2.0/trace.h:1119: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def15'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def15'>[#def15]</a> qemu-kvm-1.2.0/trace.h:21: <b>bad_sizeof</b>: Taking the size of pointer parameter "newptr" is suspicious. <a name='def16'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def16'>[#def16]</a> qemu-kvm-1.2.0/trace.h:21: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def17'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def17'>[#def17]</a> qemu-kvm-1.2.0/trace.h:2169: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_state" is suspicious. <a name='def18'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def18'>[#def18]</a> qemu-kvm-1.2.0/trace.h:2169: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. <a name='def19'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def19'>[#def19]</a> qemu-kvm-1.2.0/trace.h:903: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def20'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def20'>[#def20]</a> qemu-kvm-1.2.0/trace.h:915: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. <a name='def21'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def21'>[#def21]</a> qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def22'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def22'>[#def22]</a> qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "filename" is suspicious. <a name='def23'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def23'>[#def23]</a> qemu-kvm-1.2.0/trace.h:78: <b>bad_sizeof</b>: Taking the size of pointer parameter "format_name" is suspicious. <a name='def24'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def24'>[#def24]</a> qemu-kvm-1.2.0/trace.h:90: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def25'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def25'>[#def25]</a> qemu-kvm-1.2.0/trace.h:90: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def26'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def26'>[#def26]</a> qemu-kvm-1.2.0/trace.h:489: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def27'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def27'>[#def27]</a> qemu-kvm-1.2.0/trace.h:486: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def28'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def28'>[#def28]</a> qemu-kvm-1.2.0/trace.h:492: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def29'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def29'>[#def29]</a> qemu-kvm-1.2.0/trace.h:495: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def30'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def30'>[#def30]</a> qemu-kvm-1.2.0/trace.h:2172: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_state" is suspicious. <a name='def31'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def31'>[#def31]</a> qemu-kvm-1.2.0/trace.h:2172: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. <a name='def32'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def32'>[#def32]</a> qemu-kvm-1.2.0/trace.h:144: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. <a name='def33'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def33'>[#def33]</a> qemu-kvm-1.2.0/trace.h:141: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. <a name='def34'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def34'>[#def34]</a> qemu-kvm-1.2.0/trace.h:135: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. <a name='def35'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def35'>[#def35]</a> qemu-kvm-1.2.0/trace.h:138: <b>bad_sizeof</b>: Taking the size of pointer parameter "req" is suspicious. <a name='def36'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def36'>[#def36]</a> qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "n" is suspicious. <a name='def37'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def37'>[#def37]</a> qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "o" is suspicious. <a name='def38'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def38'>[#def38]</a> qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def39'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def39'>[#def39]</a> qemu-kvm-1.2.0/trace.h:480: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def40'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def40'>[#def40]</a> qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "n" is suspicious. <a name='def41'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def41'>[#def41]</a> qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "o" is suspicious. <a name='def42'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def42'>[#def42]</a> qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def43'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def43'>[#def43]</a> qemu-kvm-1.2.0/trace.h:483: <b>bad_sizeof</b>: Taking the size of pointer parameter "port" is suspicious. <a name='def44'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def44'>[#def44]</a> qemu-kvm-1.2.0/trace.h:117: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def45'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def45'>[#def45]</a> qemu-kvm-1.2.0/trace.h:2160: <b>bad_sizeof</b>: Taking the size of pointer parameter "cb" is suspicious. <a name='def46'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def46'>[#def46]</a> qemu-kvm-1.2.0/trace.h:2160: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. <a name='def47'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def47'>[#def47]</a> qemu-kvm-1.2.0/trace.h:2157: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. <a name='def48'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def48'>[#def48]</a> qemu-kvm-1.2.0/trace.h:2163: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. <a name='def49'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def49'>[#def49]</a> qemu-kvm-1.2.0/trace.h:2166: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. <a name='def50'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def50'>[#def50]</a> qemu-kvm-1.2.0/trace.h:2154: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def51'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def51'>[#def51]</a> qemu-kvm-1.2.0/trace.h:2154: <b>bad_sizeof</b>: Taking the size of pointer parameter "dbs" is suspicious. <a name='def52'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def52'>[#def52]</a> qemu-kvm-1.2.0/trace.h:51: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. <a name='def53'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def53'>[#def53]</a> qemu-kvm-1.2.0/trace.h:51: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def54'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def54'>[#def54]</a> qemu-kvm-1.2.0/trace.h:36: <b>bad_sizeof</b>: Taking the size of pointer parameter "elem" is suspicious. <a name='def55'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def55'>[#def55]</a> qemu-kvm-1.2.0/trace.h:36: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def56'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def56'>[#def56]</a> qemu-kvm-1.2.0/trace.h:39: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def57'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def57'>[#def57]</a> qemu-kvm-1.2.0/trace.h:45: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. <a name='def58'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def58'>[#def58]</a> qemu-kvm-1.2.0/trace.h:45: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def59'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def59'>[#def59]</a> qemu-kvm-1.2.0/trace.h:1548: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. <a name='def60'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def60'>[#def60]</a> qemu-kvm-1.2.0/trace.h:1545: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. <a name='def61'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def61'>[#def61]</a> qemu-kvm-1.2.0/trace.h:1551: <b>bad_sizeof</b>: Taking the size of pointer parameter "buf" is suspicious. <a name='def62'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def62'>[#def62]</a> qemu-kvm-1.2.0/trace.h:42: <b>bad_sizeof</b>: Taking the size of pointer parameter "elem" is suspicious. <a name='def63'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def63'>[#def63]</a> qemu-kvm-1.2.0/trace.h:42: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def64'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def64'>[#def64]</a> qemu-kvm-1.2.0/trace.h:54: <b>bad_sizeof</b>: Taking the size of pointer parameter "vdev" is suspicious. <a name='def65'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def65'>[#def65]</a> qemu-kvm-1.2.0/trace.h:822: <b>bad_sizeof</b>: Taking the size of pointer parameter "f" is suspicious. <a name='def66'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def66'>[#def66]</a> qemu-kvm-1.2.0/trace.h:819: <b>bad_sizeof</b>: Taking the size of pointer parameter "f" is suspicious. <a name='def67'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def67'>[#def67]</a> qemu-kvm-1.2.0/trace.h:1908: <b>bad_sizeof</b>: Taking the size of pointer parameter "cmd_name" is suspicious. <a name='def68'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def68'>[#def68]</a> qemu-kvm-1.2.0/trace.h:1908: <b>bad_sizeof</b>: Taking the size of pointer parameter "mon" is suspicious. <a name='def69'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def69'>[#def69]</a> qemu-kvm-1.2.0/trace.h:1029: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def70'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def70'>[#def70]</a> qemu-kvm-1.2.0/trace.h:1026: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def71'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def71'>[#def71]</a> qemu-kvm-1.2.0/trace.h:1020: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def72'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def72'>[#def72]</a> qemu-kvm-1.2.0/trace.h:1023: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def73'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def73'>[#def73]</a> qemu-kvm-1.2.0/trace.h:1017: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def74'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def74'>[#def74]</a> qemu-kvm-1.2.0/trace.h:102: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def75'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def75'>[#def75]</a> qemu-kvm-1.2.0/trace.h:108: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def76'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def76'>[#def76]</a> qemu-kvm-1.2.0/trace.h:99: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def77'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def77'>[#def77]</a> qemu-kvm-1.2.0/trace.h:105: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def78'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def78'>[#def78]</a> qemu-kvm-1.2.0/trace.h:519: <b>bad_sizeof</b>: Taking the size of pointer parameter "sts" is suspicious. <a name='def79'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def79'>[#def79]</a> qemu-kvm-1.2.0/trace.h:522: <b>bad_sizeof</b>: Taking the size of pointer parameter "schedule" is suspicious. <a name='def80'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def80'>[#def80]</a> qemu-kvm-1.2.0/trace.h:522: <b>bad_sizeof</b>: Taking the size of pointer parameter "state" is suspicious. <a name='def81'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def81'>[#def81]</a> qemu-kvm-1.2.0/trace.h:48: <b>bad_sizeof</b>: Taking the size of pointer parameter "vq" is suspicious. <a name='def82'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def82'>[#def82]</a> qemu-kvm-1.2.0/trace.h:1920: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. <a name='def83'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def83'>[#def83]</a> qemu-kvm-1.2.0/trace.h:1923: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. <a name='def84'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def84'>[#def84]</a> qemu-kvm-1.2.0/trace.h:1914: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. <a name='def85'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def85'>[#def85]</a> qemu-kvm-1.2.0/trace.h:1914: <b>bad_sizeof</b>: Taking the size of pointer parameter "evname" is suspicious. <a name='def86'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def86'>[#def86]</a> qemu-kvm-1.2.0/trace.h:525: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. <a name='def87'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def87'>[#def87]</a> qemu-kvm-1.2.0/trace.h:552: <b>bad_sizeof</b>: Taking the size of pointer parameter "owner" is suspicious. <a name='def88'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def88'>[#def88]</a> qemu-kvm-1.2.0/trace.h:501: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. <a name='def89'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def89'>[#def89]</a> qemu-kvm-1.2.0/trace.h:507: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. <a name='def90'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def90'>[#def90]</a> qemu-kvm-1.2.0/trace.h:504: <b>bad_sizeof</b>: Taking the size of pointer parameter "str" is suspicious. <a name='def91'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def91'>[#def91]</a> qemu-kvm-1.2.0/trace.h:549: <b>bad_sizeof</b>: Taking the size of pointer parameter "device" is suspicious. <a name='def92'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def92'>[#def92]</a> qemu-kvm-1.2.0/trace.h:549: <b>bad_sizeof</b>: Taking the size of pointer parameter "owner" is suspicious. <a name='def93'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def93'>[#def93]</a> qemu-kvm-1.2.0/trace.h:534: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. <a name='def94'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def94'>[#def94]</a> qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "action" is suspicious. <a name='def95'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def95'>[#def95]</a> qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def96'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def96'>[#def96]</a> qemu-kvm-1.2.0/trace.h:564: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. <a name='def97'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def97'>[#def97]</a> qemu-kvm-1.2.0/trace.h:561: <b>bad_sizeof</b>: Taking the size of pointer parameter "action" is suspicious. <a name='def98'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def98'>[#def98]</a> qemu-kvm-1.2.0/trace.h:561: <b>bad_sizeof</b>: Taking the size of pointer parameter "q" is suspicious. <a name='def99'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def99'>[#def99]</a> qemu-kvm-1.2.0/trace.h:570: <b>bad_sizeof</b>: Taking the size of pointer parameter "reason" is suspicious. <a name='def100'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def100'>[#def100]</a> qemu-kvm-1.2.0/trace.h:87: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def101'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def101'>[#def101]</a> qemu-kvm-1.2.0/trace.h:87: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def102'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def102'>[#def102]</a> qemu-kvm-1.2.0/trace.h:84: <b>bad_sizeof</b>: Taking the size of pointer parameter "mcb" is suspicious. <a name='def103'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def103'>[#def103]</a> qemu-kvm-1.2.0/trace.h:2400: <b>bad_sizeof</b>: Taking the size of pointer parameter "busname" is suspicious. <a name='def104'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def104'>[#def104]</a> qemu-kvm-1.2.0/trace.h:2388: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def105'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def105'>[#def105]</a> qemu-kvm-1.2.0/trace.h:2385: <b>bad_sizeof</b>: Taking the size of pointer parameter "msg" is suspicious. <a name='def106'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def106'>[#def106]</a> qemu-kvm-1.2.0/trace.h:1704: <b>bad_sizeof</b>: Taking the size of pointer parameter "nxt" is suspicious. <a name='def107'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def107'>[#def107]</a> qemu-kvm-1.2.0/trace.h:1707: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. <a name='def108'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def108'>[#def108]</a> qemu-kvm-1.2.0/trace.h:1707: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. <a name='def109'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def109'>[#def109]</a> qemu-kvm-1.2.0/trace.h:1710: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. <a name='def110'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def110'>[#def110]</a> qemu-kvm-1.2.0/trace.h:1710: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. <a name='def111'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def111'>[#def111]</a> qemu-kvm-1.2.0/trace.h:1713: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. <a name='def112'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def112'>[#def112]</a> qemu-kvm-1.2.0/trace.h:1713: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. <a name='def113'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def113'>[#def113]</a> qemu-kvm-1.2.0/trace.h:1716: <b>bad_sizeof</b>: Taking the size of pointer parameter "mutex" is suspicious. <a name='def114'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def114'>[#def114]</a> qemu-kvm-1.2.0/trace.h:1716: <b>bad_sizeof</b>: Taking the size of pointer parameter "self" is suspicious. <a name='def115'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def115'>[#def115]</a> qemu-kvm-1.2.0/trace.h:2295: <b>bad_sizeof</b>: Taking the size of pointer parameter "surface" is suspicious. <a name='def116'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def116'>[#def116]</a> qemu-kvm-1.2.0/trace.h:1686: <b>bad_sizeof</b>: Taking the size of pointer parameter "addr" is suspicious. <a name='def117'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def117'>[#def117]</a> qemu-kvm-1.2.0/trace.h:1974: <b>bad_sizeof</b>: Taking the size of pointer parameter "aname" is suspicious. <a name='def118'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def118'>[#def118]</a> qemu-kvm-1.2.0/trace.h:1974: <b>bad_sizeof</b>: Taking the size of pointer parameter "uname" is suspicious. <a name='def119'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def119'>[#def119]</a> qemu-kvm-1.2.0/trace.h:1125: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def120'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def120'>[#def120]</a> qemu-kvm-1.2.0/trace.h:1125: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def121'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def121'>[#def121]</a> qemu-kvm-1.2.0/trace.h:1122: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def122'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def122'>[#def122]</a> qemu-kvm-1.2.0/trace.h:1122: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def123'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def123'>[#def123]</a> qemu-kvm-1.2.0/trace.h:2034: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def124'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def124'>[#def124]</a> qemu-kvm-1.2.0/trace.h:2049: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def125'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def125'>[#def125]</a> qemu-kvm-1.2.0/trace.h:2076: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def126'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def126'>[#def126]</a> qemu-kvm-1.2.0/trace.h:2094: <b>bad_sizeof</b>: Taking the size of pointer parameter "target" is suspicious. <a name='def127'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def127'>[#def127]</a> qemu-kvm-1.2.0/trace.h:2040: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def128'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def128'>[#def128]</a> qemu-kvm-1.2.0/trace.h:2040: <b>bad_sizeof</b>: Taking the size of pointer parameter "symname" is suspicious. <a name='def129'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def129'>[#def129]</a> qemu-kvm-1.2.0/trace.h:1968: <b>bad_sizeof</b>: Taking the size of pointer parameter "version" is suspicious. <a name='def130'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def130'>[#def130]</a> qemu-kvm-1.2.0/trace.h:1971: <b>bad_sizeof</b>: Taking the size of pointer parameter "version" is suspicious. <a name='def131'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def131'>[#def131]</a> qemu-kvm-1.2.0/trace.h:1995: <b>bad_sizeof</b>: Taking the size of pointer parameter "qids" is suspicious. <a name='def132'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def132'>[#def132]</a> qemu-kvm-1.2.0/trace.h:2088: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def133'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def133'>[#def133]</a> qemu-kvm-1.2.0/trace.h:2082: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def134'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def134'>[#def134]</a> qemu-kvm-1.2.0/trace.h:114: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def135'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def135'>[#def135]</a> qemu-kvm-1.2.0/trace.h:114: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def136'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def136'>[#def136]</a> qemu-kvm-1.2.0/trace.h:111: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def137'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def137'>[#def137]</a> qemu-kvm-1.2.0/trace.h:24: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def138'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def138'>[#def138]</a> qemu-kvm-1.2.0/trace.h:717: <b>bad_sizeof</b>: Taking the size of pointer parameter "evt" is suspicious. <a name='def139'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def139'>[#def139]</a> qemu-kvm-1.2.0/trace.h:717: <b>bad_sizeof</b>: Taking the size of pointer parameter "trb" is suspicious. <a name='def140'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def140'>[#def140]</a> qemu-kvm-1.2.0/trace.h:762: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def141'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def141'>[#def141]</a> qemu-kvm-1.2.0/trace.h:774: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def142'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def142'>[#def142]</a> qemu-kvm-1.2.0/trace.h:765: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def143'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def143'>[#def143]</a> qemu-kvm-1.2.0/trace.h:768: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def144'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def144'>[#def144]</a> qemu-kvm-1.2.0/trace.h:759: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def145'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def145'>[#def145]</a> qemu-kvm-1.2.0/trace.h:18: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def146'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def146'>[#def146]</a> qemu-kvm-1.2.0/trace.h:720: <b>bad_sizeof</b>: Taking the size of pointer parameter "name" is suspicious. <a name='def147'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def147'>[#def147]</a> qemu-kvm-1.2.0/trace.h:771: <b>bad_sizeof</b>: Taking the size of pointer parameter "xfer" is suspicious. <a name='def148'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def148'>[#def148]</a> qemu-kvm-1.2.0/trace.h:147: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def149'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def149'>[#def149]</a> qemu-kvm-1.2.0/trace.h:147: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def150'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def150'>[#def150]</a> qemu-kvm-1.2.0/trace.h:1419: <b>bad_sizeof</b>: Taking the size of pointer parameter "dcmd" is suspicious. <a name='def151'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def151'>[#def151]</a> qemu-kvm-1.2.0/trace.h:1272: <b>bad_sizeof</b>: Taking the size of pointer parameter "cmd" is suspicious. <a name='def152'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def152'>[#def152]</a> qemu-kvm-1.2.0/trace.h:918: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. <a name='def153'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def153'>[#def153]</a> qemu-kvm-1.2.0/trace.h:912: <b>bad_sizeof</b>: Taking the size of pointer parameter "aurb" is suspicious. <a name='def154'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def154'>[#def154]</a> qemu-kvm-1.2.0/trace.h:1395: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. <a name='def155'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def155'>[#def155]</a> qemu-kvm-1.2.0/trace.h:1392: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. <a name='def156'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def156'>[#def156]</a> qemu-kvm-1.2.0/trace.h:960: <b>bad_sizeof</b>: Taking the size of pointer parameter "dir" is suspicious. <a name='def157'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def157'>[#def157]</a> qemu-kvm-1.2.0/trace.h:960: <b>bad_sizeof</b>: Taking the size of pointer parameter "type" is suspicious. <a name='def158'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def158'>[#def158]</a> qemu-kvm-1.2.0/trace.h:966: <b>bad_sizeof</b>: Taking the size of pointer parameter "errmsg" is suspicious. <a name='def159'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def159'>[#def159]</a> qemu-kvm-1.2.0/trace.h:909: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def160'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def160'>[#def160]</a> qemu-kvm-1.2.0/trace.h:897: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def161'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def161'>[#def161]</a> qemu-kvm-1.2.0/trace.h:900: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def162'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def162'>[#def162]</a> qemu-kvm-1.2.0/trace.h:906: <b>bad_sizeof</b>: Taking the size of pointer parameter "p" is suspicious. <a name='def163'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def163'>[#def163]</a> qemu-kvm-1.2.0/block/curl.c:296: <b>bad_sizeof</b>: Taking the size of "curl_read_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? <a name='def164'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def164'>[#def164]</a> qemu-kvm-1.2.0/block/curl.c:390: <b>bad_sizeof</b>: Taking the size of "curl_read_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? <a name='def165'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def165'>[#def165]</a> qemu-kvm-1.2.0/block/curl.c:386: <b>bad_sizeof</b>: Taking the size of "curl_size_cb(void *, size_t, size_t, void *)", which is the address of an object, is suspicious. Did you intend the size of the object itself? <a name='def166'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def166'>[#def166]</a> qemu-kvm-1.2.0/trace.h:1911: <b>bad_sizeof</b>: Taking the size of pointer parameter "mon" is suspicious. <a name='def167'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def167'>[#def167]</a> qemu-kvm-1.2.0/trace.h:2202: <b>bad_sizeof</b>: Taking the size of pointer parameter "cookie" is suspicious. <a name='def168'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def168'>[#def168]</a> qemu-kvm-1.2.0/trace.h:2364: <b>bad_sizeof</b>: Taking the size of pointer parameter "client_monitors_config" is suspicious. <a name='def169'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def169'>[#def169]</a> qemu-kvm-1.2.0/trace.h:2361: <b>bad_sizeof</b>: Taking the size of pointer parameter "heads" is suspicious. <a name='def170'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def170'>[#def170]</a> qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "last_release" is suspicious. <a name='def171'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def171'>[#def171]</a> qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def172'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def172'>[#def172]</a> qemu-kvm-1.2.0/trace.h:2274: <b>bad_sizeof</b>: Taking the size of pointer parameter "notify" is suspicious. <a name='def173'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def173'>[#def173]</a> qemu-kvm-1.2.0/trace.h:2256: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def174'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def174'>[#def174]</a> qemu-kvm-1.2.0/trace.h:2259: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def175'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def175'>[#def175]</a> qemu-kvm-1.2.0/trace.h:2265: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def176'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def176'>[#def176]</a> qemu-kvm-1.2.0/trace.h:2268: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def177'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def177'>[#def177]</a> qemu-kvm-1.2.0/hw/qxl.c:952: <b>bad_sizeof</b>: Taking the size of pointer parameter "caps" is suspicious. <a name='def178'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def178'>[#def178]</a> qemu-kvm-1.2.0/hw/qxl.c:954: <b>bad_sizeof</b>: Taking the size of pointer parameter "caps" is suspicious. <a name='def179'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def179'>[#def179]</a> qemu-kvm-1.2.0/trace.h:2226: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def180'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def180'>[#def180]</a> qemu-kvm-1.2.0/trace.h:2229: <b>bad_sizeof</b>: Taking the size of pointer parameter "log_buf" is suspicious. <a name='def181'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def181'>[#def181]</a> qemu-kvm-1.2.0/trace.h:2235: <b>bad_sizeof</b>: Taking the size of pointer parameter "desc" is suspicious. <a name='def182'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def182'>[#def182]</a> qemu-kvm-1.2.0/trace.h:2238: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def183'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def183'>[#def183]</a> qemu-kvm-1.2.0/trace.h:2331: <b>bad_sizeof</b>: Taking the size of pointer parameter "ext" is suspicious. <a name='def184'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def184'>[#def184]</a> qemu-kvm-1.2.0/trace.h:2244: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def185'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def185'>[#def185]</a> qemu-kvm-1.2.0/trace.h:1101: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def186'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def186'>[#def186]</a> qemu-kvm-1.2.0/trace.h:1107: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def187'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def187'>[#def187]</a> qemu-kvm-1.2.0/trace.h:1107: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def188'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def188'>[#def188]</a> qemu-kvm-1.2.0/trace.h:1113: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def189'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def189'>[#def189]</a> qemu-kvm-1.2.0/trace.h:1113: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def190'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def190'>[#def190]</a> qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def191'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def191'>[#def191]</a> qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def192'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def192'>[#def192]</a> qemu-kvm-1.2.0/trace.h:1110: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def193'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def193'>[#def193]</a> qemu-kvm-1.2.0/trace.h:1104: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def194'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def194'>[#def194]</a> qemu-kvm-1.2.0/trace.h:1344: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def195'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def195'>[#def195]</a> qemu-kvm-1.2.0/trace.h:1347: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def196'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def196'>[#def196]</a> qemu-kvm-1.2.0/trace.h:1311: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def197'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def197'>[#def197]</a> qemu-kvm-1.2.0/trace.h:1326: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def198'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def198'>[#def198]</a> qemu-kvm-1.2.0/trace.h:1305: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def199'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def199'>[#def199]</a> qemu-kvm-1.2.0/trace.h:1305: <b>bad_sizeof</b>: Taking the size of pointer parameter "sdev" is suspicious. <a name='def200'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def200'>[#def200]</a> qemu-kvm-1.2.0/trace.h:1308: <b>bad_sizeof</b>: Taking the size of pointer parameter "frame" is suspicious. <a name='def201'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def201'>[#def201]</a> qemu-kvm-1.2.0/trace.h:126: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. <a name='def202'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def202'>[#def202]</a> qemu-kvm-1.2.0/trace.h:132: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def203'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def203'>[#def203]</a> qemu-kvm-1.2.0/trace.h:132: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. <a name='def204'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def204'>[#def204]</a> qemu-kvm-1.2.0/trace.h:129: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def205'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def205'>[#def205]</a> qemu-kvm-1.2.0/trace.h:129: <b>bad_sizeof</b>: Taking the size of pointer parameter "job" is suspicious. <a name='def206'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def206'>[#def206]</a> qemu-kvm-1.2.0/trace.h:1044: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def207'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def207'>[#def207]</a> qemu-kvm-1.2.0/trace.h:1056: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def208'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def208'>[#def208]</a> qemu-kvm-1.2.0/trace.h:1047: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def209'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def209'>[#def209]</a> qemu-kvm-1.2.0/trace.h:1053: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def210'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def210'>[#def210]</a> qemu-kvm-1.2.0/trace.h:1050: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def211'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def211'>[#def211]</a> qemu-kvm-1.2.0/trace.h:2175: <b>bad_sizeof</b>: Taking the size of pointer parameter "display_surface" is suspicious. <a name='def212'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def212'>[#def212]</a> qemu-kvm-1.2.0/trace.h:2175: <b>bad_sizeof</b>: Taking the size of pointer parameter "filename" is suspicious. <a name='def213'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def213'>[#def213]</a> qemu-kvm-1.2.0/trace.h:93: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def214'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def214'>[#def214]</a> qemu-kvm-1.2.0/trace.h:93: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def215'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def215'>[#def215]</a> qemu-kvm-1.2.0/trace.h:96: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def216'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def216'>[#def216]</a> qemu-kvm-1.2.0/trace.h:96: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def217'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def217'>[#def217]</a> qemu-kvm-1.2.0/trace.h:1071: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def218'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def218'>[#def218]</a> qemu-kvm-1.2.0/trace.h:1074: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def219'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def219'>[#def219]</a> qemu-kvm-1.2.0/trace.h:1059: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def220'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def220'>[#def220]</a> qemu-kvm-1.2.0/trace.h:1068: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def221'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def221'>[#def221]</a> qemu-kvm-1.2.0/trace.h:1065: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def222'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def222'>[#def222]</a> qemu-kvm-1.2.0/trace.h:1062: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def223'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def223'>[#def223]</a> qemu-kvm-1.2.0/trace.h:1086: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def224'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def224'>[#def224]</a> qemu-kvm-1.2.0/trace.h:1086: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. <a name='def225'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def225'>[#def225]</a> qemu-kvm-1.2.0/trace.h:1092: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def226'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def226'>[#def226]</a> qemu-kvm-1.2.0/trace.h:1092: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. <a name='def227'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def227'>[#def227]</a> qemu-kvm-1.2.0/trace.h:1089: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def228'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def228'>[#def228]</a> qemu-kvm-1.2.0/trace.h:1089: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. <a name='def229'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def229'>[#def229]</a> qemu-kvm-1.2.0/trace.h:1095: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def230'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def230'>[#def230]</a> qemu-kvm-1.2.0/trace.h:1095: <b>bad_sizeof</b>: Taking the size of pointer parameter "table" is suspicious. <a name='def231'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def231'>[#def231]</a> qemu-kvm-1.2.0/trace.h:1197: <b>bad_sizeof</b>: Taking the size of pointer parameter "scd" is suspicious. <a name='def232'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def232'>[#def232]</a> qemu-kvm-1.2.0/trace.h:1194: <b>bad_sizeof</b>: Taking the size of pointer parameter "scd" is suspicious. <a name='def233'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def233'>[#def233]</a> qemu-kvm-1.2.0/trace.h:1038: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def234'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def234'>[#def234]</a> qemu-kvm-1.2.0/trace.h:1035: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def235'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def235'>[#def235]</a> qemu-kvm-1.2.0/trace.h:1041: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def236'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def236'>[#def236]</a> qemu-kvm-1.2.0/trace.h:1032: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def237'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def237'>[#def237]</a> qemu-kvm-1.2.0/trace.h:33: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def238'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def238'>[#def238]</a> qemu-kvm-1.2.0/trace.h:27: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def239'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def239'>[#def239]</a> qemu-kvm-1.2.0/trace.h:30: <b>bad_sizeof</b>: Taking the size of pointer parameter "ptr" is suspicious. <a name='def240'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def240'>[#def240]</a> qemu-kvm-1.2.0/trace.h:2382: <b>bad_sizeof</b>: Taking the size of pointer parameter "cookie" is suspicious. <a name='def241'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def241'>[#def241]</a> qemu-kvm-1.2.0/trace.h:81: <b>bad_sizeof</b>: Taking the size of pointer parameter "mcb" is suspicious. <a name='def242'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def242'>[#def242]</a> qemu-kvm-1.2.0/trace.h:1917: <b>bad_sizeof</b>: Taking the size of pointer parameter "data" is suspicious. <a name='def243'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def243'>[#def243]</a> qemu-kvm-1.2.0/trace.h:153: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def244'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def244'>[#def244]</a> qemu-kvm-1.2.0/trace.h:153: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def245'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def245'>[#def245]</a> qemu-kvm-1.2.0/trace.h:150: <b>bad_sizeof</b>: Taking the size of pointer parameter "acb" is suspicious. <a name='def246'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def246'>[#def246]</a> qemu-kvm-1.2.0/trace.h:150: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def247'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def247'>[#def247]</a> qemu-kvm-1.2.0/block/rbd.c:593: <b>bad_sizeof</b>: Taking the size of pointer parameter "rcb" is suspicious. <a name='def248'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def248'>[#def248]</a> qemu-kvm-1.2.0/trace.h:120: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def249'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def249'>[#def249]</a> qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "base" is suspicious. <a name='def250'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def250'>[#def250]</a> qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def251'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def251'>[#def251]</a> qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def252'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def252'>[#def252]</a> qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def253'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def253'>[#def253]</a> qemu-kvm-1.2.0/trace.h:123: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def254'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def254'>[#def254]</a> qemu-kvm-1.2.0/trace.h:162: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def255'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def255'>[#def255]</a> qemu-kvm-1.2.0/trace.h:1077: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. <a name='def256'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def256'>[#def256]</a> qemu-kvm-1.2.0/trace.h:1077: <b>bad_sizeof</b>: Taking the size of pointer parameter "l2_cache" is suspicious. <a name='def257'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def257'>[#def257]</a> qemu-kvm-1.2.0/trace.h:1083: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. <a name='def258'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def258'>[#def258]</a> qemu-kvm-1.2.0/trace.h:1083: <b>bad_sizeof</b>: Taking the size of pointer parameter "l2_cache" is suspicious. <a name='def259'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def259'>[#def259]</a> qemu-kvm-1.2.0/trace.h:1080: <b>bad_sizeof</b>: Taking the size of pointer parameter "entry" is suspicious. <a name='def260'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def260'>[#def260]</a> qemu-kvm-1.2.0/trace.h:1098: <b>bad_sizeof</b>: Taking the size of pointer parameter "s" is suspicious. <a name='def261'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def261'>[#def261]</a> qemu-kvm-1.2.0/trace.h:1698: <b>bad_sizeof</b>: Taking the size of pointer parameter "co" is suspicious. <a name='def262'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def262'>[#def262]</a> qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "from" is suspicious. <a name='def263'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def263'>[#def263]</a> qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "opaque" is suspicious. <a name='def264'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def264'>[#def264]</a> qemu-kvm-1.2.0/trace.h:1692: <b>bad_sizeof</b>: Taking the size of pointer parameter "to" is suspicious. <a name='def265'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def265'>[#def265]</a> qemu-kvm-1.2.0/trace.h:1695: <b>bad_sizeof</b>: Taking the size of pointer parameter "from" is suspicious. <a name='def266'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def266'>[#def266]</a> qemu-kvm-1.2.0/trace.h:1695: <b>bad_sizeof</b>: Taking the size of pointer parameter "to" is suspicious. <a name='def267'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def267'>[#def267]</a> qemu-kvm-1.2.0/trace.h:1458: <b>bad_sizeof</b>: Taking the size of pointer parameter "intr" is suspicious. <a name='def268'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def268'>[#def268]</a> qemu-kvm-1.2.0/trace.h:1458: <b>bad_sizeof</b>: Taking the size of pointer parameter "mode" is suspicious. <a name='def269'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def269'>[#def269]</a> qemu-kvm-1.2.0/trace.h:264: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def270'/><b>Error: <span style='background: #C0FF00;'>BAD_SIZEOF</span> (CWE-467):</b> <a href ='#def270'>[#def270]</a> qemu-kvm-1.2.0/trace.h:267: <b>bad_sizeof</b>: Taking the size of pointer parameter "bs" is suspicious. <a name='def271'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE</span> (CWE-170):</b> <a href ='#def271'>[#def271]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_true</b>: Condition "is_dot", taking true branch</span> qemu-kvm-1.2.0/block/vvfat.c:622: <b>buffer_size</b>: You might overrun the 8 byte destination string "entry->name" by writing the maximum 11 bytes from "32". <a name='def272'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE</span> (CWE-170):</b> <a href ='#def272'>[#def272]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_false</b>: Condition "is_dot", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:625: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "filename[j] != '.'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_false</b>: Condition "filename[j] != '.'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:631: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>cond_true</b>: Condition "j > 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:634: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block/vvfat.c:637: <b>buffer_size</b>: You might overrun the 8 byte destination string "entry->name" by writing the maximum 11 bytes from "32". <a name='def273'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def273'>[#def273]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1178: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1180: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block/sheepdog.c:1183: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "buf" of size 256 bytes might leave the destination string unterminated. <a name='def274'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def274'>[#def274]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:1390: <b>cond_true</b>: Condition "hci->device.lmp_name", taking true branch</span> qemu-kvm-1.2.0/hw/bt-hci.c:1391: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 248 bytes on destination array "params.name" of size 248 bytes might leave the destination string unterminated. <a name='def275'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def275'>[#def275]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2451: <b>cond_true</b>: Condition "len >= 80", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2453: <b>cond_false</b>: Condition "copy_from_user(&psinfo->pr_psargs, ts->info->arg_start, len)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2454: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_true</b>: Condition "i < len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2456: <b>cond_true</b>: Condition "psinfo->pr_psargs[i] == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_true</b>: Condition "i < len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2456: <b>cond_true</b>: Condition "psinfo->pr_psargs[i] == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2455: <b>cond_false</b>: Condition "i < len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2457: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2467: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2468: <b>cond_false</b>: Condition "0", taking false branch</span> qemu-kvm-1.2.0/linux-user/elfload.c:2469: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "psinfo->pr_fname" of size 16 bytes might leave the destination string unterminated. <a name='def276'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def276'>[#def276]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:108: <b>cond_false</b>: Condition "!v9fs_synth_fs", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:110: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:111: <b>cond_false</b>: Condition "!name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:111: <b>cond_false</b>: Condition "strlen(name) >= 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:113: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:114: <b>cond_true</b>: Condition "!parent", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>cond_true</b>: Condition "tmp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:120: <b>cond_false</b>: Condition "!__coverity_strcmp(tmp->name, name)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:123: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:124: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:119: <b>cond_false</b>: Condition "tmp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:124: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:135: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 255 bytes on destination array "node->name" of size 255 bytes might leave the destination string unterminated.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:136: <b>cond_true</b>: Condition "parent->child.lh_first != NULL", taking true branch <a name='def277'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def277'>[#def277]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:47: <b>cond_true</b>: Condition "attr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:51: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:59: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:61: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 255 bytes on destination array "node->name" of size 255 bytes might leave the destination string unterminated.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-synth.c:62: <b>cond_true</b>: Condition "parent->child.lh_first != NULL", taking true branch <a name='def278'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def278'>[#def278]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1280: <b>cond_false</b>: Condition "!drv", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1283: <b>cond_false</b>: Condition "!bs->backing_hd", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1285: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1287: <b>cond_false</b>: Condition "bs->backing_hd->keep_read_only", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1291: <b>cond_false</b>: Condition "bdrv_in_use(bs)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1291: <b>cond_false</b>: Condition "bdrv_in_use(bs->backing_hd)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1293: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1297: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 1024 bytes on destination array "filename" of size 1024 bytes might leave the destination string unterminated.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1300: <b>cond_true</b>: Condition "ro", taking true branch</span> qemu-kvm-1.2.0/block.c:1307: <b>cond_true</b>: Condition "rw_ret < 0", taking true branch <a name='def279'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def279'>[#def279]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1102: <b>cond_false</b>: Condition "parse_vdiname(s, filename, vdi, &snapid, tag) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1105: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1107: <b>cond_false</b>: Condition "s->fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1110: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1113: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1115: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1117: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1120: <b>cond_false</b>: Condition "s->flush_fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1124: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1127: <b>cond_true</b>: Condition "snapid", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1133: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1137: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1145: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1147: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block/sheepdog.c:1154: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "s->name" of size 256 bytes might leave the destination string unterminated. <a name='def280'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def280'>[#def280]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1746: <b>cond_false</b>: Condition "s->is_snapshot", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1757: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "s->inode.tag" of size 256 bytes might leave the destination string unterminated.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1763: <b>cond_true</b>: Condition "fd < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1765: <b>goto</b>: Jumping to label "cleanup"</span> qemu-kvm-1.2.0/block/sheepdog.c:1797: <b>label</b>: Reached label "cleanup" <a name='def281'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def281'>[#def281]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1821: <b>cond_true</b>: Condition "!snapid", taking true branch</span> qemu-kvm-1.2.0/block/sheepdog.c:1822: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "tag" of size 256 bytes might leave the destination string unterminated. <a name='def282'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def282'>[#def282]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1817: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "vdi" of size 256 bytes might leave the destination string unterminated.</span> qemu-kvm-1.2.0/block/sheepdog.c:1821: <b>cond_true</b>: Condition "!snapid", taking true branch <a name='def283'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def283'>[#def283]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1896: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1899: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1912: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1914: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1923: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1927: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_false</b>: Condition "!test_bit(vid, vdi_inuse)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1932: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1939: <b>cond_true</b>: Condition "ret", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1940: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_false</b>: Condition "!test_bit(vid, vdi_inuse)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1932: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1939: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1941: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1943: <b>cond_true</b>: Condition "!__coverity_strcmp(inode.name, s->name)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1943: <b>cond_true</b>: Condition "is_snapshot(&inode)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1951: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "(sn_tab + found).name" of size 256 bytes might leave the destination string unterminated.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1929: <b>cond_true</b>: Condition "found < nr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1930: <b>cond_true</b>: Condition "!test_bit(vid, vdi_inuse)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1931: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1955: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1963: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> qemu-kvm-1.2.0/block/sheepdog.c:1965: <b>if_end</b>: End of if statement <a name='def284'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def284'>[#def284]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:149: <b>cond_false</b>: Condition "!s", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:150: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:152: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "name" of size 16 bytes might leave the destination string unterminated.</span> qemu-kvm-1.2.0/os-posix.c:155: <b>cond_true</b>: Condition "prctl(15, name)", taking true branch <a name='def285'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def285'>[#def285]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:231: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:239: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:244: <b>cond_false</b>: Condition "cpu == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:247: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:283: <b>cond_true</b>: Condition "dinfo", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_true</b>: Condition "i < nb_nics", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>cond_true</b>: Condition "i == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_true</b>: Condition "i < nb_nics", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>cond_false</b>: Condition "i == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:290: <b>cond_false</b>: Condition "i < nb_nics", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:291: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:299: <b>cond_true</b>: Condition "kernel_filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:305: <b>cond_false</b>: Condition "kernel_size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:308: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:316: <b>cond_true</b>: Condition "initrd_filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:323: <b>cond_false</b>: Condition "initrd_size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:326: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/r2d.c:334: <b>cond_true</b>: Condition "kernel_cmdline", taking true branch</span> qemu-kvm-1.2.0/hw/r2d.c:335: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 256 bytes on destination array "boot_params.kernel_cmdline" of size 256 bytes might leave the destination string unterminated. <a name='def286'/><b>Error: <span style='background: #C0FF00;'>BUFFER_SIZE_WARNING</span> (CWE-170):</b> <a href ='#def286'>[#def286]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:831: <b>buffer_size_warning</b>: Calling strncpy with a maximum size argument of 16 bytes on destination array "ifr.ifr_ifrn.ifrn_name" of size 16 bytes might leave the destination string unterminated.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_true</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>goto</b>: Jumping to label "error"</span> qemu-kvm-1.2.0/qga/commands-posix.c:932: <b>label</b>: Reached label "error" <a name='def287'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def287'>[#def287]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:165: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:175: <b>switch_default</b>: Reached default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:176: <b>check_return</b>: Calling function "audio_bug(char const *, int)" without checking return value (as is done elsewhere 25 out of 26 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:192: <b>example_checked</b>: "audio_bug("audio_calloc", cond)" has its value checked in "audio_bug("audio_calloc", cond)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1003: <b>example_checked</b>: "audio_bug(<anonymous>, live < 0 || live > hw->samples)" has its value checked in "audio_bug(<anonymous>, live < 0 || live > hw->samples)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1530: <b>example_checked</b>: "audio_bug(<anonymous>, captured > sw->total_hw_samples_mixed)" has its value checked in "audio_bug(<anonymous>, captured > sw->total_hw_samples_mixed)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/audio.c:1281: <b>example_checked</b>: "audio_bug(<anonymous>, live < 0 || live > sw->hw->samples)" has its value checked in "audio_bug(<anonymous>, live < 0 || live > sw->hw->samples)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/sdlaudio.c:256: <b>example_checked</b>: "audio_bug(<anonymous>, sdl->live < 0 || sdl->live > hw->samples)" has its value checked in "audio_bug(<anonymous>, sdl->live < 0 || sdl->live > hw->samples)".</span> qemu-kvm-1.2.0/audio/audio.c:176: <b>unchecked_value</b>: No check of the return value of "audio_bug("bits_to_index", 1)". <a name='def288'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def288'>[#def288]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:162: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:164: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:166: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:166: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 0UL, 0, "dd", &header.type, &header.size)". <a name='def289'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def289'>[#def289]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:162: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:164: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:171: <b>cond_false</b>: Condition "header.size > 65536U /* 64 * 1024 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:183: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:187: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:189: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:192: <b>cond_false</b>: Condition "header.type == T_ERROR", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:199: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:201: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:246: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:247: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:247: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 8UL, 0, "q", response)". <a name='def290'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def290'>[#def290]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:271: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:273: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:275: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:275: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 0UL, 0, "dd", &header.type, &header.size)". <a name='def291'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def291'>[#def291]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:271: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:273: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:276: <b>cond_false</b>: Condition "header.size != 4UL /* sizeof (int) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:279: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:282: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:286: <b>check_return</b>: Calling function "v9fs_unmarshal(struct iovec *, int, size_t, int, char const *, ...)" without checking return value (as is done elsewhere 62 out of 66 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:639: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(iovec, 1, 8UL, 0, "sdddd", &path, &flags, &mode, &uid, &gid)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:641: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:162: <b>example_assign</b>: Assigning: "copied" = return value from "v9fs_unmarshal(out_sg, out_num, offset, bswap, "w", &str->size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:164: <b>example_checked</b>: "copied" has its value checked in "copied > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:194: <b>example_assign</b>: Assigning: "ret" = return value from "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:195: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:910: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ds", &s->msize, &version)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:911: <b>example_checked</b>: "err" has its value checked in "err < 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1239: <b>example_assign</b>: Assigning: "err" = return value from "v9fs_unmarshal(pdu->elem.out_sg, pdu->elem.out_num, offset, 1, "ddw", &fid, &newfid, &nwnames)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p.c:1240: <b>example_checked</b>: "err" has its value checked in "err < 0".</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:286: <b>unchecked_value</b>: No check of the return value of "v9fs_unmarshal(reply, 1, 8UL, 0, "d", status)". <a name='def292'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def292'>[#def292]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:505: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:507: <b>cond_false</b>: Condition "err == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:509: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:512: <b>cond_true</b>: Condition "err == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:514: <b>goto</b>: Jumping to label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:541: <b>label</b>: Reached label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:542: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:542: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". <a name='def293'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def293'>[#def293]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:445: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:448: <b>cond_false</b>: Condition "err == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:450: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:452: <b>cond_true</b>: Condition "err == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:454: <b>goto</b>: Jumping to label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:483: <b>label</b>: Reached label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:484: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:484: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". <a name='def294'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def294'>[#def294]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:609: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:611: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:614: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:618: <b>cond_true</b>: Condition "err == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:620: <b>goto</b>: Jumping to label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:652: <b>label</b>: Reached label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:654: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, path, buffer))" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:654: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, path, buffer))". <a name='def295'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def295'>[#def295]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:676: <b>cond_true</b>: Condition "fs_ctx->export_flags & 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:681: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:684: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:689: <b>cond_false</b>: Condition "write_size == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:691: <b>cond_false</b>: Condition "write_size != oldpath_size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:696: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:701: <b>cond_true</b>: Condition "err == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:703: <b>goto</b>: Jumping to label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:756: <b>label</b>: Reached label "err_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:757: <b>check_return</b>: Calling function "remove(rpath(fs_ctx, newpath, buffer))" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:757: <b>unchecked_value</b>: No check of the return value of "remove(rpath(fs_ctx, newpath, buffer))". <a name='def296'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def296'>[#def296]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "267U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:204: <b>switch_case</b>: Reached case "267U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:207: <b>cond_false</b>: Condition "e.a_text + e.a_data > max_sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:208: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:209: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:209: <b>check_return</b>: Calling function "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/loader.c:209: <b>unchecked_value</b>: No check of the return value of "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)". <a name='def297'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def297'>[#def297]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>check_return</b>: Calling function "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/loader.c:217: <b>unchecked_value</b>: No check of the return value of "lseek(fd, (((e.a_info & 0xffffU) == 0x10bU) ? 1024UL : (((e.a_info & 0xffffU) == 0xccU) ? 0UL : 32UL)), 0)". <a name='def298'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def298'>[#def298]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>check_return</b>: Calling function "lseek(fd, ehdr.e_phoff, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>unchecked_value</b>: No check of the return value of "lseek(fd, ehdr.e_phoff, 0)". <a name='def299'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def299'>[#def299]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>check_return</b>: Calling function "lseek(fd, ehdr.e_phoff, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/elf_ops.h:238: <b>unchecked_value</b>: No check of the return value of "lseek(fd, ehdr.e_phoff, 0)". <a name='def300'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def300'>[#def300]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2764: <b>cond_false</b>: Condition "dumpsize.rlim_cur == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2765: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2767: <b>cond_false</b>: Condition "core_dump_filename(ts, corefile, 4096UL /* sizeof (corefile) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2768: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2770: <b>cond_false</b>: Condition "(fd = open(corefile, 65 /* 1 | 0x40 */, 420 /* ((0x100 | 0x80) | (0x100 >> 3)) | ((0x100 >> 3) >> 3) */)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2772: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2779: <b>cond_false</b>: Condition "(mm = vma_init()) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2780: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2790: <b>cond_false</b>: Condition "dump_write(fd, &elf, 52UL /* sizeof (elf) */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2791: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2794: <b>cond_false</b>: Condition "fill_note_info(&info, signr, env) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2795: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2804: <b>cond_false</b>: Condition "dump_write(fd, &phdr, 32UL /* sizeof (phdr) */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2805: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2811: <b>cond_true</b>: Condition "1 /* 1 && (8192 - 1 & 0x2000) == 0 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2817: <b>cond_true</b>: Condition "vma != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2827: <b>cond_true</b>: Condition "vma->vma_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2828: <b>cond_true</b>: Condition "vma->vma_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2830: <b>cond_true</b>: Condition "vma->vma_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2835: <b>check_return</b>: Calling function "dump_write(int, void const *, size_t)" without checking return value (as is done elsewhere 6 out of 7 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2591: <b>example_checked</b>: "dump_write(fd, &en, 12UL)" has its value checked in "dump_write(fd, &en, 12UL) != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2593: <b>example_checked</b>: "dump_write(fd, men->name, men->namesz_rounded)" has its value checked in "dump_write(fd, men->name, men->namesz_rounded) != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2595: <b>example_checked</b>: "dump_write(fd, men->data, men->datasz_rounded)" has its value checked in "dump_write(fd, men->data, men->datasz_rounded) != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2790: <b>example_checked</b>: "dump_write(fd, &elf, 52UL)" has its value checked in "dump_write(fd, &elf, 52UL) != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2804: <b>example_checked</b>: "dump_write(fd, &phdr, 32UL)" has its value checked in "dump_write(fd, &phdr, 32UL) != 0".</span> qemu-kvm-1.2.0/linux-user/elfload.c:2835: <b>unchecked_value</b>: No check of the return value of "dump_write(fd, &phdr, 32UL)". <a name='def301'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def301'>[#def301]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:525: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_BRIDGE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:528: <b>cond_true</b>: Condition "bridge->has_helper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:529: <b>cond_true</b>: Condition "bridge->has_br", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:532: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:534: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:536: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/net/tap.c:536: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". <a name='def302'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def302'>[#def302]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:602: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_TAP", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:605: <b>cond_true</b>: Condition "tap->has_fd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_ifname", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_script", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_downscript", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_vnet_hdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:606: <b>cond_false</b>: Condition "tap->has_helper", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:611: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:614: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:616: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:618: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/net/tap.c:618: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". <a name='def303'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def303'>[#def303]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:602: <b>cond_true</b>: Condition "opts->kind == NET_CLIENT_OPTIONS_KIND_TAP", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:605: <b>cond_false</b>: Condition "tap->has_fd", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:624: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:624: <b>cond_true</b>: Condition "tap->has_helper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_ifname", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_script", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_downscript", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:625: <b>cond_false</b>: Condition "tap->has_vnet_hdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:630: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:633: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:635: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap.c:637: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/net/tap.c:637: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". <a name='def304'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def304'>[#def304]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2468: <b>check_return</b>: Calling function "setsockopt(fd, 6, 1, (char *)&val, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:2468: <b>unchecked_value</b>: No check of the return value of "setsockopt(fd, 6, 1, (char *)&val, 4U)". <a name='def305'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def305'>[#def305]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2456: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:2456: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". <a name='def306'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def306'>[#def306]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2458: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:2458: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". <a name='def307'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def307'>[#def307]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2460: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:2460: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". <a name='def308'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def308'>[#def308]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2462: <b>check_return</b>: Calling function "send(fd, (char *)buf, 3UL, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:2462: <b>unchecked_value</b>: No check of the return value of "send(fd, (char *)buf, 3UL, 0)". <a name='def309'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def309'>[#def309]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:858: <b>cond_false</b>: Condition "stdio_nb_clients >= 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:860: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:861: <b>cond_true</b>: Condition "stdio_nb_clients == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:864: <b>check_return</b>: Calling function "fcntl(0, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:864: <b>unchecked_value</b>: No check of the return value of "fcntl(0, 4, 2048)". <a name='def310'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def310'>[#def310]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1095: <b>check_return</b>: Calling function "fd_open(BlockDriverState *)" without checking return value (as is done elsewhere 6 out of 7 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1083: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) >= 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:941: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:369: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:325: <b>example_checked</b>: "fd_open(bs)" has its value checked in "fd_open(bs) < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:612: <b>example_assign</b>: Assigning: "ret" = return value from "fd_open(bs)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:613: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> qemu-kvm-1.2.0/block/raw-posix.c:1095: <b>unchecked_value</b>: No check of the return value of "fd_open(bs)". <a name='def311'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def311'>[#def311]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:324: <b>check_return</b>: Calling function "fstat(fd, &buf)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/ivshmem.c:324: <b>unchecked_value</b>: No check of the return value of "fstat(fd, &buf)". <a name='def312'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def312'>[#def312]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:660: <b>check_return</b>: Calling function "fseek(f, where, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/pc.c:660: <b>unchecked_value</b>: No check of the return value of "fseek(f, where, 0)". <a name='def313'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def313'>[#def313]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi01.c:203: <b>cond_true</b>: Condition "pfl->bs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi01.c:208: <b>check_return</b>: Calling function "bdrv_write(BlockDriverState *, int64_t, uint8_t const *, int)" without checking return value (as is done elsewhere 36 out of 40 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:813: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs, sector_num, buf, s->cluster_sectors)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:814: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1161: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, (meta.cluster_offset >> 9) + num - 1UL, buf, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1162: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:596: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, 0L, block, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:600: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:761: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(extent->file, cluster_offset, whole_grain, extent->cluster_sectors)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:763: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1697: <b>example_checked</b>: "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)" has its value checked in "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)".</span> qemu-kvm-1.2.0/hw/pflash_cfi01.c:208: <b>unchecked_value</b>: No check of the return value of "bdrv_write(pfl->bs, offset, pfl->storage + (offset << 9), offset_end - offset)". <a name='def314'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def314'>[#def314]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:234: <b>cond_true</b>: Condition "pfl->bs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:239: <b>check_return</b>: Calling function "bdrv_write(BlockDriverState *, int64_t, uint8_t const *, int)" without checking return value (as is done elsewhere 36 out of 40 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:813: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs, sector_num, buf, s->cluster_sectors)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:814: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1161: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, (meta.cluster_offset >> 9) + num - 1UL, buf, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2.c:1162: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:596: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(bs->file, 0L, block, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vdi.c:600: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:761: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_write(extent->file, cluster_offset, whole_grain, extent->cluster_sectors)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:763: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1697: <b>example_checked</b>: "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)" has its value checked in "bdrv_write(s->qcow, offset, s->cluster_buffer, 1)".</span> qemu-kvm-1.2.0/hw/pflash_cfi02.c:239: <b>unchecked_value</b>: No check of the return value of "bdrv_write(pfl->bs, offset, pfl->storage + (offset << 9), offset_end - offset)". <a name='def315'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def315'>[#def315]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:956: <b>cond_true</b>: Condition "!nr_copies", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:962: <b>cond_true</b>: Condition "aiocb_type == AIOCB_READ_UDATA", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:966: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:974: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:976: <b>cond_true</b>: Condition "s->cache_enabled", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:997: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1001: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1003: <b>cond_false</b>: Condition "wlen", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1010: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1012: <b>check_return</b>: Calling function "socket_set_cork(s->fd, 0)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> qemu-kvm-1.2.0/block/sheepdog.c:1012: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(s->fd, 0)". <a name='def316'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def316'>[#def316]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:956: <b>cond_true</b>: Condition "!nr_copies", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:962: <b>cond_true</b>: Condition "aiocb_type == AIOCB_READ_UDATA", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:966: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:974: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:976: <b>cond_true</b>: Condition "s->cache_enabled", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:993: <b>check_return</b>: Calling function "socket_set_cork(s->fd, 1)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> qemu-kvm-1.2.0/block/sheepdog.c:993: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(s->fd, 1)". <a name='def317'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def317'>[#def317]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:163: <b>cond_true</b>: Condition "!done", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:163: <b>cond_false</b>: Condition "i < ncmdline", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:187: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:188: <b>cond_false</b>: Condition "cmdline", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:191: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:193: <b>cond_true</b>: Condition "!done", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:194: <b>cond_true</b>: Condition "!prompted", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cmd.c:201: <b>check_return</b>: Calling function "main_loop_wait(0)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:478:5: <b>cond_true</b>: Condition "nonblocking", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:480:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:482:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:496:5: <b>return_wrapper</b>: The function wraps and returns the value of "os_host_main_loop_wait(timeout)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:298:5: <b>cond_true</b>: Condition "timeout < 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:304:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:308:5: <b>return_wrapper</b>: The function wraps and returns the value of "select(nfds + 1, &rfds, &wfds, &xfds, tvarg)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:310:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:499:5: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> qemu-kvm-1.2.0/cmd.c:201: <b>unchecked_value</b>: No check of the return value of "main_loop_wait(0)". <a name='def318'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def318'>[#def318]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:514: <b>cond_false</b>: Condition "parse_host_port(&saddr, host_str) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:515: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:518: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:521: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:526: <b>check_return</b>: Calling function "setsockopt(fd, 1, 2, (char const *)&val, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/net/socket.c:526: <b>unchecked_value</b>: No check of the return value of "setsockopt(fd, 1, 2, (char const *)&val, 4U)". <a name='def319'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def319'>[#def319]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:431: <b>cond_true</b>: Condition "!(env->psw.mask & 0x100000000ULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:435: <b>check_return</b>: Calling function "mmu_translate(CPUS390XState *, target_ulong, int, uint64_t, target_ulong *, int *)" without checking return value (as is done elsewhere 7 out of 8 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:400: <b>example_checked</b>: "mmu_translate(env, vaddr, rw, asc, &raddr, &prot)" has its value checked in "mmu_translate(env, vaddr, rw, asc, &raddr, &prot)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:117: <b>example_checked</b>: "mmu_translate(env, src, 0, asc, &src_phys, &flags)" has its value checked in "mmu_translate(env, src, 0, asc, &src_phys, &flags)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:87: <b>example_checked</b>: "mmu_translate(env, dest, 1, asc, &dest_phys, &flags)" has its value checked in "mmu_translate(env, dest, 1, asc, &dest_phys, &flags)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:1183: <b>example_checked</b>: "mmu_translate(env, addr, 0, asc, &ret, &flags)" has its value checked in "mmu_translate(env, addr, 0, asc, &ret, &flags)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/mem_helper.c:1090: <b>example_checked</b>: "mmu_translate(env, a1 & 0xfffffffffffff000UL, 1, mode1, &dest, &flags)" has its value checked in "mmu_translate(env, a1 & 0xfffffffffffff000UL, 1, mode1, &dest, &flags)".</span> qemu-kvm-1.2.0/target-s390x/helper.c:435: <b>unchecked_value</b>: No check of the return value of "mmu_translate(env, vaddr, 2, asc, &raddr, &prot)". <a name='def320'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def320'>[#def320]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:413: <b>check_return</b>: Calling function "fcntl(card->pipe[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/ccid-card-emulated.c:413: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[0], 4, 2048)". <a name='def321'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def321'>[#def321]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:415: <b>check_return</b>: Calling function "fcntl(card->pipe[0], 8, getpid())" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/ccid-card-emulated.c:415: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[0], 8, getpid())". <a name='def322'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def322'>[#def322]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:409: <b>cond_false</b>: Condition "pipe(card->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:412: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ccid-card-emulated.c:414: <b>check_return</b>: Calling function "fcntl(card->pipe[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/ccid-card-emulated.c:414: <b>unchecked_value</b>: No check of the return value of "fcntl(card->pipe[1], 4, 2048)". <a name='def323'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def323'>[#def323]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:646: <b>cond_false</b>: Condition "posix_aio_state", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:647: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:652: <b>cond_false</b>: Condition "qemu_pipe(fds) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:656: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:661: <b>check_return</b>: Calling function "fcntl(s->rfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/posix-aio-compat.c:661: <b>unchecked_value</b>: No check of the return value of "fcntl(s->rfd, 4, 2048)". <a name='def324'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def324'>[#def324]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:646: <b>cond_false</b>: Condition "posix_aio_state", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:647: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:652: <b>cond_false</b>: Condition "qemu_pipe(fds) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:656: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:662: <b>check_return</b>: Calling function "fcntl(s->wfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/posix-aio-compat.c:662: <b>unchecked_value</b>: No check of the return value of "fcntl(s->wfd, 4, 2048)". <a name='def325'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def325'>[#def325]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:821: <b>check_return</b>: Calling function "fcntl(0, 4, old_fd0_flags)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-char.c:821: <b>unchecked_value</b>: No check of the return value of "fcntl(0, 4, old_fd0_flags)". <a name='def326'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def326'>[#def326]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1712: <b>check_return</b>: Calling function "fcntl(d->pipe[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/qxl.c:1712: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[0], 4, 2048)". <a name='def327'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def327'>[#def327]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1714: <b>check_return</b>: Calling function "fcntl(d->pipe[0], 8, getpid())" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/qxl.c:1714: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[0], 8, getpid())". <a name='def328'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def328'>[#def328]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1707: <b>cond_false</b>: Condition "pipe(d->pipe) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1711: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1713: <b>check_return</b>: Calling function "fcntl(d->pipe[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/qxl.c:1713: <b>unchecked_value</b>: No check of the return value of "fcntl(d->pipe[1], 4, 2048)". <a name='def329'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def329'>[#def329]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:356: <b>check_return</b>: Calling function "fseek(s->stdio_file, pos, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/savevm.c:356: <b>unchecked_value</b>: No check of the return value of "fseek(s->stdio_file, pos, 0)". <a name='def330'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def330'>[#def330]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:349: <b>check_return</b>: Calling function "fseek(s->stdio_file, pos, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/savevm.c:349: <b>unchecked_value</b>: No check of the return value of "fseek(s->stdio_file, pos, 0)". <a name='def331'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def331'>[#def331]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:91: <b>cond_true</b>: Condition "req", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:91: <b>cond_true</b>: Condition "(next = req->next.tqe_next) , 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:93: <b>cond_true</b>: Condition "req->retry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:95: <b>switch</b>: Switch case value "SCSI_XFER_NONE"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:100: <b>switch_case</b>: Reached case "SCSI_XFER_NONE"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:101: <b>cond_true</b>: Condition "!req->sg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:103: <b>check_return</b>: Calling function "scsi_req_enqueue(SCSIRequest *)" without checking return value (as is done elsewhere 9 out of 11 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:133: <b>example_assign</b>: Assigning: "datalen" = return value from "scsi_req_enqueue(s->current_req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:135: <b>example_checked</b>: "datalen" has its value checked in "datalen != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:773: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(s->current->req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:774: <b>example_checked</b>: "n" has its value checked in "n".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1123: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1124: <b>example_checked</b>: "len" has its value checked in "len > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:624: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(req->sreq)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:629: <b>example_checked</b>: "n" has its value checked in "n".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:560: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req->req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:561: <b>example_checked</b>: "len" has its value checked in "len".</span> qemu-kvm-1.2.0/hw/scsi-bus.c:103: <b>unchecked_value</b>: No check of the return value of "scsi_req_enqueue(req)". <a name='def332'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def332'>[#def332]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "setsockopt(s, 1, 2, (char *)&opt, 4U /* sizeof (int) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), 16U /* sizeof (addr) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:643: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:646: <b>check_return</b>: Calling function "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/socket.c:646: <b>unchecked_value</b>: No check of the return value of "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". <a name='def333'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def333'>[#def333]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "setsockopt(s, 1, 2, (char *)&opt, 4U /* sizeof (int) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), 16U /* sizeof (addr) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:643: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:644: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/socket.c:644: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". <a name='def334'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def334'>[#def334]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:355: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:356: <b>check_return</b>: Calling function "sosendoob(so)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298:2: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301:2: <b>cond_true</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:303:3: <b>return_wrapper</b>: The function wraps and returns the value of "slirp_send(so, sb->sb_rptr, so->so_urgc, 1)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_false</b>: Condition "so->extra", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831:2: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:833:2: <b>return_wrapper</b>: The function wraps and returns the value of "send(so->s, buf, len, flags)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307:2: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:330:2: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:334:2: <b>cond_true</b>: Condition "sb->sb_rptr >= sb->sb_data + sb->sb_datalen", taking true branch</span> qemu-kvm-1.2.0/slirp/socket.c:356: <b>unchecked_value</b>: No check of the return value of "sosendoob(so)". <a name='def335'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def335'>[#def335]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1223: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1226: <b>cond_false</b>: Condition "flat", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1236: <b>cond_true</b>: Condition "compress", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1238: <b>cond_true</b>: Condition "compress", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1277: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (magic) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1280: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1282: <b>cond_false</b>: Condition "ret != 75UL /* sizeof (header) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1285: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1288: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1291: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_true</b>: Condition "i < gt_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1298: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (tmp) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1301: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_true</b>: Condition "i < gt_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1298: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (tmp) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1301: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1295: <b>cond_false</b>: Condition "i < gt_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1302: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1305: <b>check_return</b>: Calling function "lseek(fd, le64_to_cpu(header.gd_offset) << 9, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/block/vmdk.c:1305: <b>unchecked_value</b>: No check of the return value of "lseek(fd, le64_to_cpu(header.gd_offset) << 9, 0)". <a name='def336'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def336'>[#def336]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1223: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1226: <b>cond_false</b>: Condition "flat", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1236: <b>cond_true</b>: Condition "compress", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1238: <b>cond_true</b>: Condition "compress", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1277: <b>cond_false</b>: Condition "ret != 4UL /* sizeof (magic) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1280: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1282: <b>cond_false</b>: Condition "ret != 75UL /* sizeof (header) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1285: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1288: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1291: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:1294: <b>check_return</b>: Calling function "lseek(fd, le64_to_cpu(header.rgd_offset) << 9, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/block/vmdk.c:1294: <b>unchecked_value</b>: No check of the return value of "lseek(fd, le64_to_cpu(header.rgd_offset) << 9, 0)". <a name='def337'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def337'>[#def337]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:280: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:285: <b>check_return</b>: Calling function "setsockopt(sock, 1, 2, &on, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-sockets.c:285: <b>unchecked_value</b>: No check of the return value of "setsockopt(sock, 1, 2, &on, 4U)". <a name='def338'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def338'>[#def338]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "host") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "port") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:126: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:131: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:132: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:133: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:134: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:137: <b>cond_true</b>: Condition "port_offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:139: <b>cond_true</b>: Condition "strlen(addr)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:140: <b>cond_false</b>: Condition "rc != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:145: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:148: <b>cond_true</b>: Condition "e != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:153: <b>cond_false</b>: Condition "slisten < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:160: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:162: <b>check_return</b>: Calling function "setsockopt(slisten, 1, 2, (void *)&on, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-sockets.c:162: <b>unchecked_value</b>: No check of the return value of "setsockopt(slisten, 1, 2, (void *)&on, 4U)". <a name='def339'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def339'>[#def339]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "host") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:121: <b>cond_false</b>: Condition "qemu_opt_get(opts, "port") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:126: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:131: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:132: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:133: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:134: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:137: <b>cond_true</b>: Condition "port_offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:139: <b>cond_true</b>: Condition "strlen(addr)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:140: <b>cond_false</b>: Condition "rc != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:145: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:148: <b>cond_true</b>: Condition "e != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:153: <b>cond_false</b>: Condition "slisten < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:160: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:164: <b>cond_true</b>: Condition "e->ai_family == 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:166: <b>check_return</b>: Calling function "setsockopt(slisten, 41, 26, (void *)&off, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-sockets.c:166: <b>unchecked_value</b>: No check of the return value of "setsockopt(slisten, 41, 26, (void *)&off, 4U)". <a name='def340'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def340'>[#def340]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:424: <b>cond_true</b>: Condition "addr == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:427: <b>cond_false</b>: Condition "port == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:427: <b>cond_false</b>: Condition "strlen(port) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:430: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:432: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv4", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:433: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:434: <b>cond_false</b>: Condition "qemu_opt_get_bool(opts, "ipv6", false /* 0 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:435: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:437: <b>cond_false</b>: Condition "0 != (rc = getaddrinfo(addr, port, &ai, &peer))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:441: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:451: <b>cond_true</b>: Condition "addr == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:454: <b>cond_true</b>: Condition "!port", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:457: <b>cond_false</b>: Condition "0 != (rc = getaddrinfo(addr, port, &ai, &local))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:461: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:465: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:469: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:470: <b>check_return</b>: Calling function "setsockopt(sock, 1, 2, (void *)&on, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qemu-sockets.c:470: <b>unchecked_value</b>: No check of the return value of "setsockopt(sock, 1, 2, (void *)&on, 4U)". <a name='def341'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def341'>[#def341]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:393: <b>switch</b>: Switch case value "225"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:394: <b>switch_case</b>: Reached case "225"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:395: <b>cond_false</b>: Condition "devep != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:396: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:398: <b>switch</b>: Switch case value "USB_MSDM_CBW"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:399: <b>switch_case</b>: Reached case "USB_MSDM_CBW"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:400: <b>cond_false</b>: Condition "p->iov.size != 31", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:403: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:405: <b>cond_false</b>: Condition "le32_to_cpu(cbw.sig) != 1128420181", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:409: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:411: <b>cond_false</b>: Condition "cbw.lun != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:414: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:417: <b>cond_true</b>: Condition "s->data_len == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:419: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:423: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:426: <b>cond_true</b>: Condition "le32_to_cpu(s->csw.residue) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>check_return</b>: Calling function "scsi_req_enqueue(SCSIRequest *)" without checking return value (as is done elsewhere 9 out of 11 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:133: <b>example_assign</b>: Assigning: "datalen" = return value from "scsi_req_enqueue(s->current_req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp.c:135: <b>example_checked</b>: "datalen" has its value checked in "datalen != 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:773: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(s->current->req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/lsi53c895a.c:774: <b>example_checked</b>: "n" has its value checked in "n".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1123: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/megasas.c:1124: <b>example_checked</b>: "len" has its value checked in "len > 0L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:624: <b>example_assign</b>: Assigning: "n" = return value from "scsi_req_enqueue(req->sreq)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:629: <b>example_checked</b>: "n" has its value checked in "n".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:560: <b>example_assign</b>: Assigning: "len" = return value from "scsi_req_enqueue(req->req)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-uas.c:561: <b>example_checked</b>: "len" has its value checked in "len".</span> qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>unchecked_value</b>: No check of the return value of "scsi_req_enqueue(s->req)". <a name='def342'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def342'>[#def342]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:286: <b>cond_false</b>: Condition "pagetable_index >= s->max_table_entries", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:286: <b>cond_false</b>: Condition "s->pagetable[pagetable_index] == 4294967295U", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:287: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:297: <b>cond_true</b>: Condition "write", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:297: <b>cond_true</b>: Condition "s->last_bitmap_offset != bitmap_offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:302: <b>check_return</b>: Calling function "bdrv_pwrite_sync(BlockDriverState *, int64_t, void const *, int)" without checking return value (as is done elsewhere 23 out of 24 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/cow.c:122: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, offset, &bitmap, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/cow.c:123: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow.c:382: <b>example_checked</b>: "bdrv_pwrite_sync(bs->file, l2_offset + l2_index * 8UL, &tmp, 8)" has its value checked in "bdrv_pwrite_sync(bs->file, l2_offset + l2_index * 8UL, &tmp, 8) < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-cluster.c:145: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, s->l1_table_offset + 8 * l1_start_index, buf, 512)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-cluster.c:147: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:265: <b>example_assign</b>: Assigning: "ret" = return value from "bdrv_pwrite_sync(bs->file, s->refcount_table_offset + refcount_table_index * 8UL, &data64, 8)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:268: <b>example_checked</b>: "ret" has its value checked in "ret < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vmdk.c:785: <b>example_checked</b>: "bdrv_pwrite_sync(extent->file, (int64_t)m_data->l2_offset * 512L + m_data->l2_index * 4UL, &m_data->offset, 4)" has its value checked in "bdrv_pwrite_sync(extent->file, (int64_t)m_data->l2_offset * 512L + m_data->l2_index * 4UL, &m_data->offset, 4) < 0".</span> qemu-kvm-1.2.0/block/vpc.c:302: <b>unchecked_value</b>: No check of the return value of "bdrv_pwrite_sync(bs->file, bitmap_offset, bitmap, s->bitmap_size)". <a name='def343'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def343'>[#def343]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1274: <b>check_return</b>: Calling function "strstart(char const *, char const *, char const **)" without checking return value (as is done elsewhere 74 out of 76 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:95: <b>example_checked</b>: "strstart(file, "nbd:", &host_spec)" has its value checked in "strstart(file, "nbd:", &host_spec)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1055: <b>example_checked</b>: "strstart(filename, "/dev/fd", NULL)" has its value checked in "strstart(filename, "/dev/fd", NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:170: <b>example_checked</b>: "strstart(filename, "rbd:", &start)" has its value checked in "strstart(filename, "rbd:", &start)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1024: <b>example_checked</b>: "strstart(dirname, "fat:", NULL)" has its value checked in "strstart(dirname, "fat:", NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dump.c:847: <b>example_checked</b>: "strstart(file, "file:", &p)" has its value checked in "strstart(file, "file:", &p)".</span> qemu-kvm-1.2.0/block/sheepdog.c:1274: <b>unchecked_value</b>: No check of the return value of "strstart(filename, "sheepdog:", &vdiname)". <a name='def344'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def344'>[#def344]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:1094: <b>check_return</b>: Calling function "strstart(char const *, char const *, char const **)" without checking return value (as is done elsewhere 74 out of 76 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:95: <b>example_checked</b>: "strstart(file, "nbd:", &host_spec)" has its value checked in "strstart(file, "nbd:", &host_spec)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/raw-posix.c:1055: <b>example_checked</b>: "strstart(filename, "/dev/fd", NULL)" has its value checked in "strstart(filename, "/dev/fd", NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:170: <b>example_checked</b>: "strstart(filename, "rbd:", &start)" has its value checked in "strstart(filename, "rbd:", &start)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1024: <b>example_checked</b>: "strstart(dirname, "fat:", NULL)" has its value checked in "strstart(dirname, "fat:", NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dump.c:847: <b>example_checked</b>: "strstart(file, "file:", &p)" has its value checked in "strstart(file, "file:", &p)".</span> qemu-kvm-1.2.0/block/sheepdog.c:1094: <b>unchecked_value</b>: No check of the return value of "strstart(filename, "sheepdog:", (char const **)&filename)". <a name='def345'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def345'>[#def345]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:738: <b>cond_false</b>: Condition "!len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:740: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:743: <b>cond_true</b>: Condition "rc >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:745: <b>cond_true</b>: Condition "ret != len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:749: <b>check_return</b>: Calling function "socket_set_cork(csock, 0)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> qemu-kvm-1.2.0/nbd.c:749: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(csock, 0)". <a name='def346'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def346'>[#def346]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:738: <b>cond_false</b>: Condition "!len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:740: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:741: <b>check_return</b>: Calling function "socket_set_cork(csock, 1)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:60:5: <b>return_wrapper</b>: The function wraps and returns the value of "setsockopt(fd, 6, 3, &v, 4U)"</span> qemu-kvm-1.2.0/nbd.c:741: <b>unchecked_value</b>: No check of the return value of "socket_set_cork(csock, 1)". <a name='def347'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def347'>[#def347]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:147: <b>check_return</b>: Calling function "fcntl(fd, 4, f & 0xfffffffffffff7ff)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/oslib-posix.c:147: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, f & 0xfffffffffffff7ff)". <a name='def348'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def348'>[#def348]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:154: <b>check_return</b>: Calling function "fcntl(fd, 4, f | 0x800)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/oslib-posix.c:154: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, f | 0x800)". <a name='def349'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def349'>[#def349]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:161: <b>check_return</b>: Calling function "fcntl(fd, 2, f | 1)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/oslib-posix.c:161: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 2, f | 1)". <a name='def350'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def350'>[#def350]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:242: <b>check_return</b>: Calling function "stat(path, &st)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/oslib-posix.c:242: <b>unchecked_value</b>: No check of the return value of "stat(path, &st)". <a name='def351'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def351'>[#def351]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:87: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:106: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:121: <b>cond_true</b>: Condition "dinfo", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_true</b>: Condition "i < 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_true</b>: Condition "i < 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:129: <b>cond_false</b>: Condition "i < 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:131: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:134: <b>cond_true</b>: Condition "bios_name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:139: <b>cond_true</b>: Condition "bios_filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist.c:140: <b>check_return</b>: Calling function "load_image_targphys(char const *, target_phys_addr_t, uint64_t)" without checking return value (as is done elsewhere 50 out of 60 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:73: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:77: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:400: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(info->kernel_filename, entry, info->ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:404: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:238: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(kernel_filename, 0UL, flash_size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:241: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:79: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(li->image_filename, 1073758208U, ram_size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:84: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:56: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:61: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> qemu-kvm-1.2.0/hw/milkymist.c:140: <b>unchecked_value</b>: No check of the return value of "load_image_targphys(bios_filename, 8781824U, 524288UL)". <a name='def352'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def352'>[#def352]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:335: <b>cond_true</b>: Condition "(ret = so->s = qemu_socket(2, SOCK_STREAM, 0)) >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:343: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:343: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". <a name='def353'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def353'>[#def353]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:335: <b>cond_true</b>: Condition "(ret = so->s = qemu_socket(2, SOCK_STREAM, 0)) >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:341: <b>check_return</b>: Calling function "setsockopt(s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:341: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 2, (char *)&opt, 4U)". <a name='def354'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def354'>[#def354]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:431: <b>check_return</b>: Calling function "setsockopt(s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:431: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 10, (char *)&opt, 4U)". <a name='def355'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def355'>[#def355]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:429: <b>check_return</b>: Calling function "setsockopt(s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:429: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 1, 2, (char *)&opt, 4U)". <a name='def356'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def356'>[#def356]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_true</b>: Condition "inso->so_state & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:419: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:423: <b>cond_false</b>: Condition "(s = accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:426: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:433: <b>check_return</b>: Calling function "setsockopt(s, 6, 1, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:433: <b>unchecked_value</b>: No check of the return value of "setsockopt(s, 6, 1, (char *)&opt, 4U)". <a name='def357'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def357'>[#def357]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:105: <b>cond_true</b>: Condition "spt->fd < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:109: <b>cond_false</b>: Condition "spt->fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:111: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:113: <b>cond_true</b>: Condition "len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tftp.c:114: <b>check_return</b>: Calling function "lseek(spt->fd, block_nr * 512U, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/tftp.c:114: <b>unchecked_value</b>: No check of the return value of "lseek(spt->fd, block_nr * 512U, 0)". <a name='def358'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def358'>[#def358]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "channel != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "({...})", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:35: <b>cond_false</b>: Condition "client_fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:38: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>check_return</b>: Calling function "fcntl(client_fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>unchecked_value</b>: No check of the return value of "fcntl(client_fd, 4, 2048)". <a name='def359'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def359'>[#def359]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "115"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:349: <b>switch_case</b>: Reached case "115"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:351: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "110"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:352: <b>switch_case</b>: Reached case "110"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:356: <b>cond_false</b>: Condition "seen_cache", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:358: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:360: <b>cond_false</b>: Condition "bdrv_parse_cache_flags(optarg, &flags) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:362: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:363: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:365: <b>switch_case</b>: Reached case "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:366: <b>cond_false</b>: Condition "seen_aio", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:368: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:370: <b>cond_true</b>: Condition "!__coverity_strcmp(optarg, "native")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:372: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:376: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:377: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "115"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:349: <b>switch_case</b>: Reached case "115"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:351: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "98"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:379: <b>switch_case</b>: Reached case "98"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:381: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "112"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:382: <b>switch_case</b>: Reached case "112"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:384: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:387: <b>cond_false</b>: Condition "li < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:387: <b>cond_false</b>: Condition "li > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:389: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:391: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "111"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:392: <b>switch_case</b>: Reached case "111"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:394: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:396: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:397: <b>cond_false</b>: Condition "dev_offset < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:399: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:400: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "114"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:401: <b>switch_case</b>: Reached case "114"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:404: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "114"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:401: <b>switch_case</b>: Reached case "114"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:404: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_true</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:348: <b>switch</b>: Switch case value "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:405: <b>switch_case</b>: Reached case "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:407: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:408: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:409: <b>cond_false</b>: Condition "partition < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:409: <b>cond_false</b>: Condition "partition > 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:410: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:411: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:449: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:347: <b>cond_false</b>: Condition "(ch = getopt_long(argc, argv, sopt, lopt, &opt_ind)) != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:450: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:452: <b>cond_false</b>: Condition "argc - optind != 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:458: <b>cond_false</b>: Condition "disconnect", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:470: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:472: <b>cond_false</b>: Condition "device", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:522: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:524: <b>cond_false</b>: Condition "device != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:527: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:534: <b>cond_false</b>: Condition "(ret = bdrv_open(bs, srcpath, flags, NULL)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:537: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:541: <b>cond_true</b>: Condition "partition != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:543: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:546: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:551: <b>cond_true</b>: Condition "sockpath", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:555: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:557: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:559: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:561: <b>cond_false</b>: Condition "device", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:569: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:580: <b>cond_false</b>: Condition "chdir("/") < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:582: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:585: <b>check_return</b>: Calling function "main_loop_wait(0)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:478:5: <b>cond_true</b>: Condition "nonblocking", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:480:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:482:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:496:5: <b>return_wrapper</b>: The function wraps and returns the value of "os_host_main_loop_wait(timeout)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:298:5: <b>cond_true</b>: Condition "timeout < 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:304:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:308:5: <b>return_wrapper</b>: The function wraps and returns the value of "select(nfds + 1, &rfds, &wfds, &xfds, tvarg)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:310:5: <b>cond_true</b>: Condition "timeout > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:314:5: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/main-loop.c:499:5: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> qemu-kvm-1.2.0/qemu-nbd.c:585: <b>unchecked_value</b>: No check of the return value of "main_loop_wait(0)". <a name='def360'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def360'>[#def360]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:460: <b>cond_false</b>: Condition "qemu_rbd_parsename(filename, pool, 128 /* sizeof (pool) */, snap_buf, 128 /* sizeof (snap_buf) */, s->name, 96 /* sizeof (s->name) */, conf, 1024 /* sizeof (conf) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:465: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:469: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:472: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:475: <b>cond_true</b>: Condition "snap_buf[0] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:486: <b>cond_true</b>: Condition "flags & 0x20", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:488: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:496: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:498: <b>cond_false</b>: Condition "strstr(conf, "conf=") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:501: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:503: <b>cond_true</b>: Condition "conf[0] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:505: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:508: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:512: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:515: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:518: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:521: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:524: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:527: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:529: <b>cond_true</b>: Condition "s->snap != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:533: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:537: <b>check_return</b>: Calling function "fcntl(s->fds[0], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/block/rbd.c:537: <b>unchecked_value</b>: No check of the return value of "fcntl(s->fds[0], 4, 2048)". <a name='def361'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def361'>[#def361]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:460: <b>cond_false</b>: Condition "qemu_rbd_parsename(filename, pool, 128 /* sizeof (pool) */, snap_buf, 128 /* sizeof (snap_buf) */, s->name, 96 /* sizeof (s->name) */, conf, 1024 /* sizeof (conf) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:465: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:469: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:472: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:475: <b>cond_true</b>: Condition "snap_buf[0] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:486: <b>cond_true</b>: Condition "flags & 0x20", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:488: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:496: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:498: <b>cond_false</b>: Condition "strstr(conf, "conf=") == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:501: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:503: <b>cond_true</b>: Condition "conf[0] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:505: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:508: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:512: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:515: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:518: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:521: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:524: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:527: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:529: <b>cond_true</b>: Condition "s->snap != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:533: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:538: <b>check_return</b>: Calling function "fcntl(s->fds[1], 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/block/rbd.c:538: <b>unchecked_value</b>: No check of the return value of "fcntl(s->fds[1], 4, 2048)". <a name='def362'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def362'>[#def362]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:209: <b>cond_false</b>: Condition "s->efd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:210: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-aio.c:211: <b>check_return</b>: Calling function "fcntl(s->efd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/linux-aio.c:211: <b>unchecked_value</b>: No check of the return value of "fcntl(s->efd, 4, 2048)". <a name='def363'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def363'>[#def363]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1225y.c:56: <b>cond_true</b>: Condition "s->file", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1225y.c:57: <b>check_return</b>: Calling function "fseek(s->file, addr, 0)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/ds1225y.c:57: <b>unchecked_value</b>: No check of the return value of "fseek(s->file, addr, 0)". <a name='def364'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def364'>[#def364]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:161: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:163: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:176: <b>cond_true</b>: Condition "cpu_model == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:184: <b>cond_false</b>: Condition "cpu == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:187: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:196: <b>cond_false</b>: Condition "ram_size > (268435456UL /* 0x100 << 20 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:201: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:214: <b>cond_true</b>: Condition "bios_name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:217: <b>cond_true</b>: Condition "filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:219: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:221: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:227: <b>cond_true</b>: Condition "bios_size > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:227: <b>cond_true</b>: Condition "bios_size <= 4194304 /* 4 * 1024 * 1024 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>cond_false</b>: Condition "__s == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:228: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mips_r4k.c:234: <b>check_return</b>: Calling function "load_image_targphys(char const *, target_phys_addr_t, uint64_t)" without checking return value (as is done elsewhere 50 out of 60 times).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:73: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/an5206.c:77: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:400: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(info->kernel_filename, entry, info->ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:404: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:238: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(kernel_filename, 0UL, flash_size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/armv7m.c:241: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:79: <b>example_assign</b>: Assigning: "image_size" = return value from "load_image_targphys(li->image_filename, 1073758208U, ram_size)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cris-boot.c:84: <b>example_checked</b>: "image_size" has its value checked in "image_size < 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:56: <b>example_assign</b>: Assigning: "kernel_size" = return value from "load_image_targphys(kernel_filename, 65536U, ram_size - 65536UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/dummy_m68k.c:61: <b>example_checked</b>: "kernel_size" has its value checked in "kernel_size < 0".</span> qemu-kvm-1.2.0/hw/mips_r4k.c:234: <b>unchecked_value</b>: No check of the return value of "load_image_targphys(filename, 532676608UL, 4194304UL)". <a name='def365'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def365'>[#def365]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:372: <b>cond_false</b>: Condition "bind(so->s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:375: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:378: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/udp.c:378: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". <a name='def366'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def366'>[#def366]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:372: <b>cond_false</b>: Condition "bind(so->s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:375: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:376: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/udp.c:376: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 2, (char *)&opt, 4U)". <a name='def367'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def367'>[#def367]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_true</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:306: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:306: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)". <a name='def368'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def368'>[#def368]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_true</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:309: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:314: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:316: <b>cond_true</b>: Condition "src.sin_addr.s_addr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:297: <b>cond_false</b>: Condition "so->so_state & 0x1000", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:299: <b>cond_true</b>: Condition "so->so_tcpcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:301: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:303: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:304: <b>cond_false</b>: Condition "so->so_state & (12288 /* 0x1000 | 0x2000 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:309: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:316: <b>cond_false</b>: Condition "src.sin_addr.s_addr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:318: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:320: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:296: <b>cond_false</b>: Condition "so != &slirp->tcb", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:322: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:324: <b>cond_true</b>: Condition "so != &slirp->udb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:325: <b>cond_true</b>: Condition "so->so_state & 0x1000", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:328: <b>check_return</b>: Calling function "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:328: <b>unchecked_value</b>: No check of the return value of "getsockname(so->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&src}), &src_len)". <a name='def369'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def369'>[#def369]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:156: <b>check_return</b>: Calling function "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:156: <b>unchecked_value</b>: No check of the return value of "getsockname(s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)". <a name='def370'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def370'>[#def370]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:201: <b>switch_default</b>: Reached default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_true</b>: Condition "so->s < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_false</b>: Condition "*__errno_location() == 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:217: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 10, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:217: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 10, (char *)&opt, 4U)". <a name='def371'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def371'>[#def371]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:201: <b>switch_default</b>: Reached default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_true</b>: Condition "so->s < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:212: <b>cond_false</b>: Condition "*__errno_location() == 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:215: <b>check_return</b>: Calling function "setsockopt(so->s, 1, 2, (char *)&opt, 4U)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:215: <b>unchecked_value</b>: No check of the return value of "setsockopt(so->s, 1, 2, (char *)&opt, 4U)". <a name='def372'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def372'>[#def372]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:267: <b>check_return</b>: Calling function "select(0, &fdset, &fdset, &fdset, &t)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/slirp/misc.c:267: <b>unchecked_value</b>: No check of the return value of "select(0, &fdset, &fdset, &fdset, &t)". <a name='def373'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def373'>[#def373]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>cond_true</b>: Condition "(fd = open("/dev/net/tun", 2)) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:43: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:44: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:47: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:51: <b>cond_true</b>: Condition "*vnet_hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:54: <b>cond_true</b>: Condition "ioctl(fd, 2147767503UL /* (((2U << 0 + 8 + 8 + 14) | (0x54 << 0 + 8)) | (0xcf << 0)) | (sizeof (unsigned int) << 0 + 8 + 8) */, &features) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:54: <b>cond_true</b>: Condition "features & 16384", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:58: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:60: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:62: <b>cond_true</b>: Condition "vnet_hdr_required", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:62: <b>cond_false</b>: Condition "!*vnet_hdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:67: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:70: <b>cond_true</b>: Condition "ifname[0] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:71: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:73: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:75: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:83: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/tap-linux.c:85: <b>check_return</b>: Calling function "fcntl(fd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/net/tap-linux.c:85: <b>unchecked_value</b>: No check of the return value of "fcntl(fd, 4, 2048)". <a name='def374'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def374'>[#def374]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:80: <b>cond_false</b>: Condition "m->m_hdr.mh_len <= 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:83: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:90: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/sbuf.c:93: <b>check_return</b>: Calling function "sosendoob(so)" without checking return value. It wraps a library function that may fail and return an error code.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298:2: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301:2: <b>cond_true</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:303:3: <b>return_wrapper</b>: The function wraps and returns the value of "slirp_send(so, sb->sb_rptr, so->so_urgc, 1)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828:2: <b>cond_false</b>: Condition "so->extra", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831:2: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:833:2: <b>return_wrapper</b>: The function wraps and returns the value of "send(so->s, buf, len, flags)"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307:2: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:330:2: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:334:2: <b>cond_true</b>: Condition "sb->sb_rptr >= sb->sb_data + sb->sb_datalen", taking true branch</span> qemu-kvm-1.2.0/slirp/sbuf.c:93: <b>unchecked_value</b>: No check of the return value of "sosendoob(so)". <a name='def375'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def375'>[#def375]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:70: <b>cond_false</b>: Condition "qemu_pipe(notifier_fds) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:73: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:75: <b>cond_false</b>: Condition "!p->pool", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:78: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:80: <b>cond_false</b>: Condition "!p->completed", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:87: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:91: <b>check_return</b>: Calling function "fcntl(p->rfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:91: <b>unchecked_value</b>: No check of the return value of "fcntl(p->rfd, 4, 2048)". <a name='def376'/><b>Error: <span style='background: #C0FF00;'>CHECKED_RETURN</span> (CWE-252):</b> <a href ='#def376'>[#def376]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:70: <b>cond_false</b>: Condition "qemu_pipe(notifier_fds) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:73: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:75: <b>cond_false</b>: Condition "!p->pool", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:78: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:80: <b>cond_false</b>: Condition "!p->completed", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:87: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:92: <b>check_return</b>: Calling function "fcntl(p->wfd, 4, 2048)" without checking return value. This library function may fail and return an error code.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-coth.c:92: <b>unchecked_value</b>: No check of the return value of "fcntl(p->wfd, 4, 2048)". <a name='def377'/><b>Error: <span style='background: #C0FF00;'>CHROOT</span> (CWE-243):</b> <a href ='#def377'>[#def377]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "61"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5714: <b>switch_case</b>: Reached case "61"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5715: <b>cond_false</b>: Condition "!(p = lock_user_string(arg1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5716: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5717: <b>chroot_call</b>: Calling chroot: "chroot(p)".</span> qemu-kvm-1.2.0/linux-user/syscall.c:5717: <b>chroot</b>: Calling function "get_errno(abi_long)" after chroot() but before calling chdir("/"). <a name='def378'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def378'>[#def378]</a> qemu-kvm-1.2.0/target-arm/helper.c:565: <b>result_independent_of_operands</b>: (ret & (20 /* 0xa << 1 */)) >> 5 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def379'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def379'>[#def379]</a> qemu-kvm-1.2.0/hw/megasas.c:1222: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def380'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def380'>[#def380]</a> qemu-kvm-1.2.0/hw/megasas.c:910: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def381'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def381'>[#def381]</a> qemu-kvm-1.2.0/qapi/opts-visitor.c:287: <b>result_independent_of_operands</b>: -9223372036854775808LL /* -9223372036854775807L - 1 */ <= val is always true regardless of the values of its operands. This occurs as the logical second operand of '&&'. <a name='def382'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def382'>[#def382]</a> qemu-kvm-1.2.0/hw/megasas.c:1105: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def383'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def383'>[#def383]</a> qemu-kvm-1.2.0/hw/megasas.c:954: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def384'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def384'>[#def384]</a> qemu-kvm-1.2.0/hw/megasas.c:695: <b>result_independent_of_operands</b>: (sdev->id & 255) >> 8 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def385'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def385'>[#def385]</a> qemu-kvm-1.2.0/hw/pxa2xx_lcd.c:622: <b>result_independent_of_operands</b>: *((uint16_t *)src) & (16777216 /* 1 << 24 */) is always 0 regardless of the values of its operands. This occurs as the operand of assignment. <a name='def386'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def386'>[#def386]</a> qemu-kvm-1.2.0/target-sh4/translate.c:1414: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. <a name='def387'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def387'>[#def387]</a> qemu-kvm-1.2.0/target-sh4/translate.c:1418: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. <a name='def388'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def388'>[#def388]</a> qemu-kvm-1.2.0/target-sh4/translate.c:1423: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. <a name='def389'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def389'>[#def389]</a> qemu-kvm-1.2.0/target-sh4/translate.c:1430: <b>result_independent_of_operands</b>: ((ctx->opcode >> 4) & 7) < 8 is always true regardless of the values of its operands. This occurs as the logical first operand of '&&'. <a name='def390'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def390'>[#def390]</a> qemu-kvm-1.2.0/target-s390x/int_helper.c:60: <b>result_independent_of_operands</b>: (__uint128_t)env->regs[r1] << 64 is 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. <a name='def391'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def391'>[#def391]</a> qemu-kvm-1.2.0/target-s390x/int_helper.c:40: <b>result_independent_of_operands</b>: res >> 64 is 0 regardless of the values of its operands. This occurs as the operand of assignment. <a name='def392'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def392'>[#def392]</a> qemu-kvm-1.2.0/hw/imx_ccm.c:156: <b>result_independent_of_operands</b>: (s->ccmr & (6U /* 3 << 1 */)) == 1 is always false regardless of the values of its operands. This occurs as the logical operand of if. <a name='def393'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def393'>[#def393]</a> qemu-kvm-1.2.0/hw/sun4c_intctl.c:129: <b>result_independent_of_operands</b>: s->reg & 0x80000000U is always 0 regardless of the values of its operands. This occurs as the logical operand of '!'. <a name='def394'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def394'>[#def394]</a> qemu-kvm-1.2.0/hw/max111x.c:76: <b>missing_parentheses</b>: ((value & 4294967279U /* ~(1 << 4) */) >> 2 /* 2 + 0 */) & 4 is always 0 regardless of the values of its operands. This occurs as the bitwise first operand of '|'. Did you intend to apply '&' to 2 /* 2 + 0 */ and 4? If so, parentheses would be required to force this interpretation. <a name='def395'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def395'>[#def395]</a> qemu-kvm-1.2.0/hw/spapr_vscsi.c:574: <b>pointless_expression</b>: The expression cdb[1] & 1 || cdb[1] & 1 does not accomplish anything because it evaluates to either of its identical operands, cdb[1] & 1. Did you intend the operands to be different? <a name='def396'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def396'>[#def396]</a> qemu-kvm-1.2.0/buffered_file.c:226: <b>result_independent_of_operands</b>: new_rate > 18446744073709551615UL is always false regardless of the values of its operands. This occurs as the logical operand of if. <a name='def397'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def397'>[#def397]</a> qemu-kvm-1.2.0/sparc-dis.c:3053: <b>result_independent_of_operands</b>: (unsigned int)((insn >> 14) & 31) < 32 is always true regardless of the values of its operands. This occurs as the logical operand of if. <a name='def398'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def398'>[#def398]</a> qemu-kvm-1.2.0/sparc-dis.c:3061: <b>result_independent_of_operands</b>: (unsigned int)((insn >> 25) & 31) < 32 is always true regardless of the values of its operands. This occurs as the logical operand of if. <a name='def399'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def399'>[#def399]</a> /usr/include/bits/stdio2.h:287: <b>pointless_expression</b>: The expression 1 /* !0 */ || 1 /* !0 */ does not accomplish anything because it evaluates to either of its identical operands, 1 /* !0 */. Did you intend the operands to be different? <a name='def400'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def400'>[#def400]</a> qemu-kvm-1.2.0/target-i386/arch_memory_mapping.c:134: <b>result_independent_of_operands</b>: (pde & 2088960) << 19 is 0 regardless of the values of its operands. This occurs as the bitwise second operand of '|'. <a name='def401'/><b>Error: <span style='background: #C0FF00;'>CONSTANT_EXPRESSION_RESULT</span> (CWE-569):</b> <a href ='#def401'>[#def401]</a> qemu-kvm-1.2.0/hw/qdev-addr.c:52: <b>result_independent_of_operands</b>: (uint64_t)value <= 18446744073709551615UL /* (uint64_t)~((target_phys_addr_t)0) */ is always true regardless of the values of its operands. This occurs as the logical operand of if. <a name='def402'/><b>Error: <span style='background: #C0FF00;'>COPY_PASTE_ERROR</span>:</b> <a href ='#def402'>[#def402]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/seg_helper.c:128: <b>original</b>: "lduw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + index + 2U) + guest_base))" looks like the original copy.</span> qemu-kvm-1.2.0/target-i386/seg_helper.c:131: <b>copy_paste_error</b>: "lduw_le_p" in "lduw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + index + 4U) + guest_base))" looks like a copy-paste error. Should it say "ldl_le_p" instead? <a name='def403'/><b>Error: <span style='background: #C0FF00;'>COPY_PASTE_ERROR</span>:</b> <a href ='#def403'>[#def403]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/seg_helper.c:352: <b>original</b>: "stw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + (34 + i * 4)) + guest_base), env->segs[i].selector)" looks like the original copy.</span> qemu-kvm-1.2.0/target-i386/seg_helper.c:336: <b>copy_paste_error</b>: "stw_le_p" in "stw_le_p((void *)((unsigned long)(target_ulong)(env->tr.base + (72 + i * 4)) + guest_base), env->segs[i].selector)" looks like a copy-paste error. Should it say "stl_le_p" instead? <a name='def404'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def404'>[#def404]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:122: <b>assignment</b>: Assigning: "head" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:128: <b>null</b>: At condition "head == NULL", the value of "head" must be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:128: <b>dead_error_condition</b>: The condition "head == NULL" must be true.</span> qemu-kvm-1.2.0/migration.c:132: <b>dead_error_begin</b>: Execution cannot reach this statement "caps->next = g_malloc0(16UL);". <a name='def405'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def405'>[#def405]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2404: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2403: <b>equality_cond</b>: Jumping to case "6".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2407: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[6,6], [10,10]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2407: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2417: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def406'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def406'>[#def406]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2430: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2429: <b>equality_cond</b>: Jumping to case "7".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2433: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[7,7], [11,11]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2433: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2442: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def407'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def407'>[#def407]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2352: <b>equality_cond</b>: Jumping to case "4".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2353: <b>equality_cond</b>: Jumping to case "8".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2356: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [8,8]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2356: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2366: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def408'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def408'>[#def408]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2377: <b>equality_cond</b>: Jumping to case "5".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2378: <b>equality_cond</b>: Jumping to case "9".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2381: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[5,5], [9,9]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2381: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2391: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def409'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def409'>[#def409]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def410'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def410'>[#def410]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def411'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def411'>[#def411]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2035: <b>assignment</b>: Assigning: "rm" = "modrm & 7".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2152: <b>between</b>: When switching on "rm", the value of "rm" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2152: <b>dead_error_condition</b>: The switch value "rm" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:2178: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def412'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def412'>[#def412]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2208: <b>assignment</b>: Assigning: "mod" = "(modrm >> 6) & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>between</b>: When switching on "mod", the value of "mod" must be between 0 and 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2209: <b>cond_cannot_single</b>: Condition "mod == 3", taking false branch. Now the value of "mod" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>cannot_single</b>: When switching on "mod", the value of "mod" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2222: <b>dead_error_condition</b>: The switch value "mod" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:2231: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def413'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def413'>[#def413]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2208: <b>assignment</b>: Assigning: "mod" = "(modrm >> 6) & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>between</b>: When switching on "mod", the value of "mod" must be between 0 and 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2209: <b>cond_cannot_single</b>: Condition "mod == 3", taking false branch. Now the value of "mod" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>cannot_single</b>: When switching on "mod", the value of "mod" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:2237: <b>dead_error_condition</b>: The switch value "mod" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:2246: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def414'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def414'>[#def414]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:11077: <b>dead_error_condition</b>: The switch value "(ctx->opcode >> 6) & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/target-mips/translate.c:11097: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def415'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def415'>[#def415]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:521: <b>assignment</b>: Assigning: "addr" &= "7U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:522: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:522: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/serial.c:523: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def416'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def416'>[#def416]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:374: <b>assignment</b>: Assigning: "addr" &= "7U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:376: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/serial.c:376: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/serial.c:377: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def417'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def417'>[#def417]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1305: <b>dead_error_condition</b>: The switch value "(insn >> 25) & 0xfU" cannot reach the default case.</span> qemu-kvm-1.2.0/target-unicore32/translate.c:1431: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def418'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def418'>[#def418]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/fpu_helper.c:260: <b>dead_error_condition</b>: The switch value "(env->fpscr >> 0) & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/target-ppc/fpu_helper.c:273: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def419'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def419'>[#def419]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def420'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def420'>[#def420]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def421'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def421'>[#def421]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def422'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def422'>[#def422]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:557: <b>assignment</b>: Assigning: "nslots" = "31".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:565: <b>const</b>: At condition "nslots < 1", the value of "nslots" must be equal to 31.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:565: <b>dead_error_condition</b>: The condition "nslots < 1" cannot be true.</span> qemu-kvm-1.2.0/hw/shpc.c:566: <b>dead_error_line</b>: Execution cannot reach this statement "return 0;". <a name='def423'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def423'>[#def423]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:557: <b>assignment</b>: Assigning: "nslots" = "31".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>const</b>: At condition "nslots > 31", the value of "nslots" must be equal to 31.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>dead_error_condition</b>: The condition "nslots > 31" cannot be true.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>const</b>: At condition "nslots + 1 > 32", the value of "nslots" must be equal to 31.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/shpc.c:568: <b>dead_error_condition</b>: The condition "nslots + 1 > 32" cannot be true.</span> qemu-kvm-1.2.0/hw/shpc.c:571: <b>dead_error_line</b>: Execution cannot reach this statement "return -22;". <a name='def424'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def424'>[#def424]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking false branch. Now the value of "xop" is between 20 and 23.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking false branch. Now the value of "xop" is between 4 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking true branch. Now the value of "xop" is between 8 and 19.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_const</b>: Condition "xop != 14U", taking false branch. Now the value of "xop" is equal to 14.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_const</b>: Condition "xop >= 32U", taking false branch. Now the value of "xop" is equal to 30.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4966: <b>intervals</b>: When switching on "xop", the value of "xop" must be in one of the following intervals: {[4,7], [14,14], [20,23], [30,30]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4966: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/translate.c:5056: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def425'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def425'>[#def425]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop >= 32U", taking true branch. Now the value of "xop" is between 32 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop < 36U", taking false branch. Now the value of "xop" is between 36 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5059: <b>cond_between</b>: Condition "xop < 40U", taking true branch. Now the value of "xop" is between 36 and 39.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>between</b>: When switching on "xop", the value of "xop" must be between 36 and 39.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_single</b>: Condition "xop == 60U", taking false branch. Now the value of "xop" cannot be equal to 60.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_set</b>: Condition "xop == 62U", taking false branch. Now the value of "xop" cannot be equal to any of {60, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 31U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 61U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4963: <b>cond_cannot_set</b>: Condition "xop == 14U", taking false branch. Now the value of "xop" cannot be equal to any of {14, 31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4963: <b>cond_cannot_set</b>: Condition "xop == 30U", taking false branch. Now the value of "xop" cannot be equal to any of {14, 30, 31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>cannot_set</b>: When switching on "xop", the value of "xop" cannot be equal to any of {14, 30, 31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:5063: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/translate.c:5114: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def426'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def426'>[#def426]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4674: <b>assignment</b>: Assigning: "xop" = "(insn >> 19) & 0x3fU".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 4U", taking false branch. Now the value of "xop" is between 4 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 7U", taking true branch. Now the value of "xop" is between 8 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop < 20U", taking false branch. Now the value of "xop" is between 20 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 23U", taking true branch. Now the value of "xop" is between 24 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop <= 29U", taking false branch. Now the value of "xop" is between 30 and 63.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_between</b>: Condition "xop > 44U", taking false branch. Now the value of "xop" is between 30 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop >= 32U", taking true branch. Now the value of "xop" is between 32 and 44.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4911: <b>cond_between</b>: Condition "xop < 36U", taking true branch. Now the value of "xop" is between 32 and 35.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>between</b>: When switching on "xop", the value of "xop" must be between 32 and 35.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_single</b>: Condition "xop == 60U", taking false branch. Now the value of "xop" cannot be equal to 60.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4683: <b>cond_cannot_set</b>: Condition "xop == 62U", taking false branch. Now the value of "xop" cannot be equal to any of {60, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 31U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4698: <b>cond_cannot_set</b>: Condition "xop == 61U", taking false branch. Now the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>cannot_set</b>: When switching on "xop", the value of "xop" cannot be equal to any of {31, 60, 61, 62}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4915: <b>dead_error_condition</b>: The switch value "xop" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/translate.c:4960: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def427'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def427'>[#def427]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def428'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def428'>[#def428]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def429'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def429'>[#def429]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def430'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def430'>[#def430]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def431'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def431'>[#def431]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1356: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1356: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> qemu-kvm-1.2.0/linux-user/elfload.c:1357: <b>dead_error_begin</b>: Execution cannot reach this statement "len = strlen(k_platform) + ...". <a name='def432'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def432'>[#def432]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1382: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1382: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> qemu-kvm-1.2.0/linux-user/elfload.c:1383: <b>dead_error_line</b>: Execution cannot reach this statement "size += 2;". <a name='def433'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def433'>[#def433]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1355: <b>assignment</b>: Assigning: "k_platform" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1420: <b>null</b>: At condition "k_platform", the value of "k_platform" must be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1420: <b>dead_error_condition</b>: The condition "k_platform" cannot be true.</span> qemu-kvm-1.2.0/linux-user/elfload.c:1421: <b>dead_error_begin</b>: Execution cannot reach this statement "do { sp -= 4U; ({ a...". <a name='def434'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def434'>[#def434]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1439: <b>assignment</b>: Assigning: "stack_adjust" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1453: <b>const</b>: At condition "stack_adjust == 8", the value of "stack_adjust" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1453: <b>dead_error_condition</b>: The condition "stack_adjust == 8" cannot be true.</span> qemu-kvm-1.2.0/tcg/i386/tcg-target.c:1455: <b>dead_error_line</b>: Execution cannot reach this statement "tcg_out_pop(s, 1);". <a name='def435'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def435'>[#def435]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5110: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:5111: <b>dead_error_line</b>: Execution cannot reach this statement "goto badframe;". <a name='def436'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def436'>[#def436]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5114: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:5115: <b>dead_error_line</b>: Execution cannot reach this statement "goto badframe;". <a name='def437'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def437'>[#def437]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:482: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:482: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:482: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def438'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def438'>[#def438]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:487: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:487: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:487: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_MigrationStats(m...". <a name='def439'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def439'>[#def439]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:492: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:492: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:492: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_MigrationStats(m...". <a name='def440'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def440'>[#def440]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:497: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:497: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:497: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_XBZRLECacheStats...". <a name='def441'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def441'>[#def441]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:479: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:502: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:502: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:502: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def442'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def442'>[#def442]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:29: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:32: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:32: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:32: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def443'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def443'>[#def443]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1331: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1355: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1355: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1355: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_PciDeviceInfoLis...". <a name='def444'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def444'>[#def444]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1277: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1284: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1284: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1284: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def445'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def445'>[#def445]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1277: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1289: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1289: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1289: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def446'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def446'>[#def446]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1409: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1409: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1409: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def447'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def447'>[#def447]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1441: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1441: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1441: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def448'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def448'>[#def448]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1397: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1447: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1447: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1447: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_PciBridgeInfo(m,...". <a name='def449'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def449'>[#def449]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1096: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1096: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1096: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def450'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def450'>[#def450]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1101: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1101: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1101: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def451'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def451'>[#def451]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1106: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1106: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1106: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def452'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def452'>[#def452]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1111: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1111: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1111: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def453'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def453'>[#def453]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1116: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1116: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1116: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def454'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def454'>[#def454]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1091: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1122: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1122: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1122: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_SpiceChannelList...". <a name='def455'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def455'>[#def455]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:920: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:926: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:926: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:926: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def456'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def456'>[#def456]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:920: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:931: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:931: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:931: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def457'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def457'>[#def457]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1582: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1587: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1587: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1587: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def458'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def458'>[#def458]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1582: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1592: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1592: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1592: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_NewImageMode(m, ...". <a name='def459'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def459'>[#def459]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2737: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2741: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2741: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2741: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def460'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def460'>[#def460]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:678: <b>assignment</b>: Assigning: "fn" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:680: <b>const</b>: At condition "fn", the value of "fn" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_vscsi.c:680: <b>dead_error_condition</b>: The condition "fn" cannot be true.</span> qemu-kvm-1.2.0/hw/spapr_vscsi.c:682: <b>dead_error_line</b>: Execution cannot reach this statement ";". <a name='def461'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def461'>[#def461]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:538: <b>assignment</b>: Assigning: "value" &= "0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:541: <b>const</b>: At condition "value & 0x40UL", the value of "value" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/xilinx_axienet.c:541: <b>dead_error_condition</b>: The condition "value & 0x40UL" cannot be true.</span> qemu-kvm-1.2.0/hw/xilinx_axienet.c:542: <b>dead_error_begin</b>: Execution cannot reach this statement "miiclkdiv = value & 0x3fUL;". <a name='def462'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def462'>[#def462]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4921: <b>cond_const</b>: Condition "err", taking false branch. Now the value of "err" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4932: <b>assignment</b>: Assigning: "err" |= "({...})".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4936: <b>assignment</b>: Assigning: "err" |= "({...})".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4939: <b>const</b>: At condition "err", the value of "err" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4939: <b>dead_error_condition</b>: The condition "err" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:4940: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". <a name='def463'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def463'>[#def463]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:4925: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:4926: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". <a name='def464'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def464'>[#def464]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5062: <b>cond_const</b>: Condition "err", taking false branch. Now the value of "err" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5073: <b>assignment</b>: Assigning: "err" |= "({...})".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5077: <b>assignment</b>: Assigning: "err" |= "({...})".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5079: <b>assignment</b>: Assigning: "err" |= "({...})".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5081: <b>const</b>: At condition "err", the value of "err" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5081: <b>dead_error_condition</b>: The condition "err" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:5082: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". <a name='def465'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def465'>[#def465]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:5066: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> qemu-kvm-1.2.0/linux-user/signal.c:5067: <b>dead_error_line</b>: Execution cannot reach this statement "goto give_sigsegv;". <a name='def466'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def466'>[#def466]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:260: <b>assignment</b>: Assigning: "addr" = "(addr >> 9) & 0xfUL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:261: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 15.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:261: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/cuda.c:316: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def467'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def467'>[#def467]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:332: <b>assignment</b>: Assigning: "addr" = "(addr >> 9) & 0xfUL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:335: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 15.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cuda.c:335: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/cuda.c:400: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def468'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def468'>[#def468]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def469'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def469'>[#def469]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def470'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def470'>[#def470]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def471'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def471'>[#def471]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:166: <b>cond_at_least</b>: Condition "count < 64L", taking false branch. Now the value of "count" is at least 64.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>at_least</b>: At condition "count < 64L", the value of "count" must be at least 64.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:162: <b>cond_cannot_single</b>: Condition "count == 0L", taking false branch. Now the value of "count" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>cannot_single</b>: At condition "count < 64L", the value of "count" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>dead_error_condition</b>: The condition "count < 64L" cannot be true.</span> qemu-kvm-1.2.0/fpu/softfloat-macros.h:171: <b>dead_error_line</b>: Execution cannot reach this expression "a0 >> (count & 0x3fL)" inside statement "z1 = ((count < 64L) ? a0 >>...". <a name='def472'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def472'>[#def472]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/helper.c:2030: <b>dead_error_condition</b>: The switch value "desc & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/helper.c:2059: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def473'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def473'>[#def473]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/helper.c:2139: <b>dead_error_condition</b>: The switch value "desc & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/helper.c:2153: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def474'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def474'>[#def474]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:944: <b>cond_null</b>: Condition "penv", taking false branch. Now the value of "penv" is NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:953: <b>null</b>: At condition "penv", the value of "penv" must be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cpus.c:953: <b>dead_error_condition</b>: The condition "penv" cannot be true.</span> qemu-kvm-1.2.0/cpus.c:954: <b>dead_error_begin</b>: Execution cannot reach this statement "penv->stop = 0U;". <a name='def475'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def475'>[#def475]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4375: <b>dead_error_condition</b>: The condition "flags & 0U" cannot be true.</span> qemu-kvm-1.2.0/linux-user/syscall.c:4376: <b>dead_error_line</b>: Execution cannot reach this statement "return -22;". <a name='def476'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def476'>[#def476]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def477'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def477'>[#def477]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def478'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def478'>[#def478]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def479'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def479'>[#def479]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4957: <b>assignment</b>: Assigning: "disp" = "0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5063: <b>cond_const</b>: Condition "disp", taking false branch. Now the value of "disp" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5063: <b>cond_at_least</b>: Condition "disp", taking true branch. Now the value of "disp" is at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5066: <b>at_least</b>: At condition "(bfd_signed_vma)disp >= 0L", the value of "disp" must be at least 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5066: <b>dead_error_condition</b>: The condition "(bfd_signed_vma)disp >= 0L" must be true.</span> qemu-kvm-1.2.0/i386-dis.c:5071: <b>dead_error_line</b>: Execution cannot reach this statement "if (modrm.mod != 1){ *obu...". <a name='def480'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def480'>[#def480]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4957: <b>assignment</b>: Assigning: "disp" = "0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5139: <b>cond_const</b>: Condition "disp", taking false branch. Now the value of "disp" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5139: <b>cond_at_least</b>: Condition "disp", taking true branch. Now the value of "disp" is at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5142: <b>at_least</b>: At condition "(bfd_signed_vma)disp >= 0L", the value of "disp" must be at least 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:5142: <b>dead_error_condition</b>: The condition "(bfd_signed_vma)disp >= 0L" must be true.</span> qemu-kvm-1.2.0/i386-dis.c:5147: <b>dead_error_line</b>: Execution cannot reach this statement "if (modrm.mod != 1){ *obu...". <a name='def481'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def481'>[#def481]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc.c:826: <b>dead_error_condition</b>: The switch value "(env->spr[986] >> 24) & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/ppc.c:839: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def482'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def482'>[#def482]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc.c:916: <b>dead_error_condition</b>: The switch value "(env->spr[986] >> 30) & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/ppc.c:929: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def483'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def483'>[#def483]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:373: <b>cond_at_least</b>: Condition "(int64_t)r == 0L", taking false branch. Now the value of "r" is at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>at_least</b>: At condition "(int64_t)r < 0L", the value of "r" must be at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:373: <b>cond_cannot_single</b>: Condition "(int64_t)r == 0L", taking false branch. Now the value of "r" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>cannot_single</b>: At condition "(int64_t)r < 0L", the value of "r" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/cc_helper.c:375: <b>dead_error_condition</b>: The condition "(int64_t)r < 0L" cannot be true.</span> qemu-kvm-1.2.0/target-s390x/cc_helper.c:376: <b>dead_error_line</b>: Execution cannot reach this statement "return 1U;". <a name='def484'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def484'>[#def484]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6629: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6631: <b>equality_cond</b>: Jumping to case "0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6632: <b>equality_cond</b>: Jumping to case "1U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6633: <b>equality_cond</b>: Jumping to case "2U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6634: <b>equality_cond</b>: Jumping to case "3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6646: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6646: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:6651: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def485'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def485'>[#def485]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6629: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6630: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6630: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:6635: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def486'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def486'>[#def486]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6671: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6673: <b>equality_cond</b>: Jumping to case "0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6674: <b>equality_cond</b>: Jumping to case "1U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6675: <b>equality_cond</b>: Jumping to case "2U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6676: <b>equality_cond</b>: Jumping to case "3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6687: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6687: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:6692: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def487'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def487'>[#def487]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6671: <b>assignment</b>: Assigning: "i" = "(insn >> 23) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6672: <b>between</b>: When switching on "i", the value of "i" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6672: <b>dead_error_condition</b>: The switch value "i" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:6677: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def488'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def488'>[#def488]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6949: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 0xfU".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6980: <b>cond_const</b>: Condition "op1 != 13U", taking false branch. Now the value of "op1" is equal to 13.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6980: <b>cond_const</b>: Condition "op1 != 15U", taking false branch. Now the value of "op1" is equal to 15.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6987: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 15.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:6987: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:7113: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def489'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def489'>[#def489]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7201: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_const</b>: Condition "op1", taking false branch. Now the value of "op1" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_between</b>: Condition "op1", taking true branch. Now the value of "op1" is between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7209: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7209: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:7222: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def490'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def490'>[#def490]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7201: <b>assignment</b>: Assigning: "op1" = "(insn >> 21) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_const</b>: Condition "op1", taking false branch. Now the value of "op1" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7202: <b>cond_between</b>: Condition "op1", taking true branch. Now the value of "op1" is between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7227: <b>between</b>: When switching on "op1", the value of "op1" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7227: <b>dead_error_condition</b>: The switch value "op1" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:7240: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def491'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def491'>[#def491]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7132: <b>assignment</b>: Assigning: "sh" = "(insn >> 5) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7133: <b>cond_between</b>: Condition "sh == 0U", taking false branch. Now the value of "sh" is between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>between</b>: When switching on "sh", the value of "sh" must be between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7133: <b>cond_cannot_single</b>: Condition "sh == 0U", taking false branch. Now the value of "sh" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>cannot_single</b>: When switching on "sh", the value of "sh" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7277: <b>dead_error_condition</b>: The switch value "sh" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:7284: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def492'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def492'>[#def492]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:475: <b>assignment</b>: Assigning: "saddr" = "(addr >> serial->it_shift) & 1UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:478: <b>between</b>: When switching on "saddr", the value of "saddr" must be between 0 and 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:478: <b>dead_error_condition</b>: The switch value "saddr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/escc.c:563: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def493'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def493'>[#def493]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:577: <b>assignment</b>: Assigning: "saddr" = "(addr >> serial->it_shift) & 1UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:580: <b>between</b>: When switching on "saddr", the value of "saddr" must be between 0 and 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/escc.c:580: <b>dead_error_condition</b>: The switch value "saddr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/escc.c:597: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def494'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def494'>[#def494]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3939: <b>assignment</b>: Assigning: "nregs" = "((insn >> 8) & 3U) + 1U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3941: <b>between</b>: When switching on "nregs", the value of "nregs" must be between 1 and 4.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3941: <b>dead_error_condition</b>: The switch value "nregs" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:3963: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def495'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def495'>[#def495]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3870: <b>assignment</b>: Assigning: "size" = "(insn >> 10) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3924: <b>equality_cond</b>: Jumping to case "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3978: <b>equality_cond</b>: Jumping to case "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3928: <b>equality_cond</b>: Jumping to case "1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3981: <b>equality_cond</b>: Jumping to case "1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3932: <b>equality_cond</b>: Jumping to case "2".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3984: <b>equality_cond</b>: Jumping to case "2".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3977: <b>between</b>: When switching on "size", the value of "size" must be between 0 and 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3977: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:3987: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def496'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def496'>[#def496]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3870: <b>assignment</b>: Assigning: "size" = "(insn >> 10) & 3U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>between</b>: When switching on "size", the value of "size" must be between 0 and 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3871: <b>cond_cannot_single</b>: Condition "size == 3", taking false branch. Now the value of "size" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>cannot_single</b>: When switching on "size", the value of "size" cannot be equal to 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:3923: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:3936: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def497'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def497'>[#def497]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def498'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def498'>[#def498]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def499'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def499'>[#def499]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def500'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def500'>[#def500]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def501'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def501'>[#def501]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1590: <b>assignment</b>: Assigning: "addr" = "addr1 & 7U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1594: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1594: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/ide/core.c:1645: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def502'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def502'>[#def502]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1602: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1602: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> qemu-kvm-1.2.0/hw/ide/core.c:1605: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_feature;". <a name='def503'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def503'>[#def503]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1610: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1610: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> qemu-kvm-1.2.0/hw/ide/core.c:1613: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_nsector;". <a name='def504'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def504'>[#def504]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1618: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1618: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> qemu-kvm-1.2.0/hw/ide/core.c:1621: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_sector;". <a name='def505'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def505'>[#def505]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1626: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1626: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> qemu-kvm-1.2.0/hw/ide/core.c:1629: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_lcyl;". <a name='def506'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def506'>[#def506]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1593: <b>assignment</b>: Assigning: "hob" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1634: <b>const</b>: At condition "hob", the value of "hob" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:1634: <b>dead_error_condition</b>: The condition "!hob" must be true.</span> qemu-kvm-1.2.0/hw/ide/core.c:1637: <b>dead_error_line</b>: Execution cannot reach this statement "ret = s->hob_hcyl;". <a name='def507'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def507'>[#def507]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:914: <b>assignment</b>: Assigning: "addr" &= "7U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:917: <b>cond_const</b>: Condition "addr != 7U", taking false branch. Now the value of "addr" is equal to 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:920: <b>between</b>: When switching on "addr", the value of "addr" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/core.c:920: <b>dead_error_condition</b>: The switch value "addr" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/ide/core.c:966: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def508'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def508'>[#def508]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1168: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1168: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1168: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def509'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def509'>[#def509]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1173: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1173: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1173: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def510'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def510'>[#def510]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1178: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1178: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1178: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def511'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def511'>[#def511]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1183: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1183: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1183: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def512'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def512'>[#def512]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1188: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1188: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1188: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def513'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def513'>[#def513]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1164: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1193: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1193: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1193: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def514'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def514'>[#def514]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:699: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:705: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:705: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:705: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def515'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def515'>[#def515]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:768: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:768: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:768: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockDeviceInfo(...". <a name='def516'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def516'>[#def516]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:773: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:773: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:773: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def517'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def517'>[#def517]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:761: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:778: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:778: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:778: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockDeviceIoSta...". <a name='def518'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def518'>[#def518]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:869: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:872: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:872: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:872: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def519'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def519'>[#def519]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:869: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:878: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:878: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:878: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_BlockStats(m, (o...". <a name='def520'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def520'>[#def520]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:641: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:641: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:641: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def521'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def521'>[#def521]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:646: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:646: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:646: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def522'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def522'>[#def522]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:651: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:651: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:651: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def523'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def523'>[#def523]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:635: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:656: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:656: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:656: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int(m, (obj ? &(...". <a name='def524'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def524'>[#def524]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:977: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:977: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:977: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def525'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def525'>[#def525]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:982: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:982: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:982: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def526'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def526'>[#def526]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:987: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:987: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:987: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def527'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def527'>[#def527]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:992: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:992: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:992: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def528'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def528'>[#def528]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:973: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:997: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:997: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:997: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_VncClientInfoLis...". <a name='def529'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def529'>[#def529]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1857: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1857: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1857: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def530'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def530'>[#def530]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1862: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1862: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1862: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def531'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def531'>[#def531]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1867: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1867: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1867: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def532'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def532'>[#def532]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1872: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1872: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1872: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def533'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def533'>[#def533]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1854: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1877: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1877: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1877: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint32(m, (obj ?...". <a name='def534'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def534'>[#def534]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2335: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2338: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2338: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2338: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def535'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def535'>[#def535]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2335: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2343: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2343: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2343: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def536'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def536'>[#def536]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2285: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2288: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2288: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2288: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_size(m, (obj ? &...". <a name='def537'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def537'>[#def537]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2285: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2293: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2293: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2293: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def538'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def538'>[#def538]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2158: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2158: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2158: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def539'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def539'>[#def539]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2163: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2163: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2163: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def540'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def540'>[#def540]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2168: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2168: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2168: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def541'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def541'>[#def541]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2173: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2173: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2173: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def542'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def542'>[#def542]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2178: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2178: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2178: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def543'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def543'>[#def543]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2155: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2183: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2183: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2183: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def544'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def544'>[#def544]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2068: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2068: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2068: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def545'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def545'>[#def545]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2073: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2073: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2073: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def546'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def546'>[#def546]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2078: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2078: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2078: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def547'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def547'>[#def547]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2083: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2083: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2083: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def548'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def548'>[#def548]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2088: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2088: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2088: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def549'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def549'>[#def549]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2093: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2093: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2093: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_size(m, (obj ? &...". <a name='def550'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def550'>[#def550]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2098: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2098: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2098: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def551'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def551'>[#def551]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2103: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2103: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2103: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def552'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def552'>[#def552]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2108: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2108: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2108: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def553'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def553'>[#def553]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2065: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2113: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2113: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2113: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def554'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def554'>[#def554]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1963: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1963: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1963: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def555'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def555'>[#def555]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1968: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1968: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1968: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def556'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def556'>[#def556]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1973: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1973: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1973: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def557'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def557'>[#def557]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1978: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1978: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1978: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def558'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def558'>[#def558]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1983: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1983: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1983: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def559'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def559'>[#def559]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1988: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1988: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1988: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def560'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def560'>[#def560]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1993: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1993: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1993: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def561'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def561'>[#def561]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1998: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1998: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:1998: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def562'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def562'>[#def562]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2003: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2003: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2003: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def563'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def563'>[#def563]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2008: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2008: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2008: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def564'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def564'>[#def564]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2013: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2013: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2013: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def565'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def565'>[#def565]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2018: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2018: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2018: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_StringList(m, (o...". <a name='def566'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def566'>[#def566]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:1960: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2023: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2023: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2023: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_StringList(m, (o...". <a name='def567'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def567'>[#def567]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2228: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2228: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2228: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def568'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def568'>[#def568]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2233: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2233: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2233: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint16(m, (obj ?...". <a name='def569'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def569'>[#def569]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2238: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2238: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2238: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def570'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def570'>[#def570]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2225: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2243: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2243: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2243: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_uint16(m, (obj ?...". <a name='def571'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def571'>[#def571]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2508: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2508: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2508: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_int32(m, (obj ? ...". <a name='def572'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def572'>[#def572]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2513: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2513: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2513: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def573'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def573'>[#def573]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2505: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2518: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2518: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2518: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def574'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def574'>[#def574]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2603: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2607: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2607: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2607: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def575'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def575'>[#def575]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2603: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2612: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qapi-visit.c:2612: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qapi-visit.c:2612: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_bool(m, (obj ? &...". <a name='def576'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def576'>[#def576]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1494: <b>assignment</b>: Assigning: "fpu_insn" = "(dc->ir >> 7) & 7U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1496: <b>between</b>: When switching on "fpu_insn", the value of "fpu_insn" must be between 0 and 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1496: <b>dead_error_condition</b>: The switch value "fpu_insn" cannot reach the default case.</span> qemu-kvm-1.2.0/target-microblaze/translate.c:1578: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def577'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def577'>[#def577]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:650: <b>assignment</b>: Assigning: "subcode" = "dc->imm & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:661: <b>cond_const</b>: Condition "subcode >= 1U", taking false branch. Now the value of "subcode" is equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:661: <b>cond_between</b>: Condition "subcode >= 1U", taking true branch. Now the value of "subcode" is between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:666: <b>between</b>: When switching on "subcode", the value of "subcode" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:666: <b>dead_error_condition</b>: The switch value "subcode" cannot reach the default case.</span> qemu-kvm-1.2.0/target-microblaze/translate.c:683: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def578'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def578'>[#def578]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3082: <b>equality_cond</b>: Jumping to case "14".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3083: <b>equality_cond</b>: Jumping to case "30".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3084: <b>equality_cond</b>: Jumping to case "31".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3089: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[14,14], [30,31]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3089: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3099: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def579'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def579'>[#def579]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3173: <b>equality_cond</b>: Jumping to case "148".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3174: <b>equality_cond</b>: Jumping to case "149".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3175: <b>equality_cond</b>: Jumping to case "150".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3178: <b>between</b>: When switching on "op", the value of "op" must be between 148 and 150.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3178: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3188: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def580'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def580'>[#def580]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3194: <b>equality_cond</b>: Jumping to case "152".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3195: <b>equality_cond</b>: Jumping to case "153".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3196: <b>equality_cond</b>: Jumping to case "154".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3200: <b>between</b>: When switching on "op", the value of "op" must be between 152 and 154.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3200: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3210: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def581'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def581'>[#def581]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3218: <b>equality_cond</b>: Jumping to case "164".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3219: <b>equality_cond</b>: Jumping to case "165".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3222: <b>between</b>: When switching on "op", the value of "op" must be between 164 and 165.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3222: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3229: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def582'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def582'>[#def582]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1522: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1523: <b>equality_cond</b>: Jumping to case "24".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1524: <b>equality_cond</b>: Jumping to case "26".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1521: <b>equality_cond</b>: Jumping to case "8".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1539: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[8,8], [10,10], [24,24], [26,26]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1539: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1548: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def583'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def583'>[#def583]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1556: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1557: <b>equality_cond</b>: Jumping to case "25".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1558: <b>equality_cond</b>: Jumping to case "27".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1555: <b>equality_cond</b>: Jumping to case "9".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1571: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[9,9], [11,11], [25,25], [27,27]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1571: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1580: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def584'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def584'>[#def584]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1760: <b>equality_cond</b>: Jumping to case "118".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1761: <b>equality_cond</b>: Jumping to case "119".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1764: <b>between</b>: When switching on "op", the value of "op" must be between 118 and 119.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1764: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1773: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def585'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def585'>[#def585]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1784: <b>equality_cond</b>: Jumping to case "128".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1785: <b>equality_cond</b>: Jumping to case "129".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1786: <b>equality_cond</b>: Jumping to case "130".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1789: <b>between</b>: When switching on "op", the value of "op" must be between 128 and 130.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1789: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1799: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def586'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def586'>[#def586]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1637: <b>equality_cond</b>: Jumping to case "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1643: <b>equality_cond</b>: Jumping to case "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1638: <b>equality_cond</b>: Jumping to case "33".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1644: <b>equality_cond</b>: Jumping to case "33".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1639: <b>equality_cond</b>: Jumping to case "48".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1647: <b>equality_cond</b>: Jumping to case "48".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1640: <b>equality_cond</b>: Jumping to case "49".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1650: <b>equality_cond</b>: Jumping to case "49".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1656: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[32,33], [48,49]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1656: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1665: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def587'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def587'>[#def587]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1637: <b>equality_cond</b>: Jumping to case "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1638: <b>equality_cond</b>: Jumping to case "33".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1639: <b>equality_cond</b>: Jumping to case "48".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1640: <b>equality_cond</b>: Jumping to case "49".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1642: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[32,33], [48,49]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1642: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1653: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def588'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def588'>[#def588]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1709: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1719: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1710: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1722: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1729: <b>between</b>: When switching on "op", the value of "op" must be between 90 and 91.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1729: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1736: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def589'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def589'>[#def589]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1709: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1710: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1718: <b>between</b>: When switching on "op", the value of "op" must be between 90 and 91.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1718: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:1725: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def590'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def590'>[#def590]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1978: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1979: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1976: <b>equality_cond</b>: Jumping to case "12".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1977: <b>equality_cond</b>: Jumping to case "13".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1980: <b>equality_cond</b>: Jumping to case "28".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1987: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[10,13], [28,28]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:1987: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2012: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def591'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def591'>[#def591]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2049: <b>equality_cond</b>: Jumping to case "150".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2062: <b>equality_cond</b>: Jumping to case "150".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2045: <b>equality_cond</b>: Jumping to case "36".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2075: <b>equality_cond</b>: Jumping to case "36".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2048: <b>equality_cond</b>: Jumping to case "38".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2078: <b>equality_cond</b>: Jumping to case "38".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2044: <b>equality_cond</b>: Jumping to case "4".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2059: <b>equality_cond</b>: Jumping to case "4".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2058: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [36,36], [38,38], [150,150]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2058: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2084: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def592'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def592'>[#def592]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2021: <b>equality_cond</b>: Jumping to case "29".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2031: <b>const</b>: When switching on "op", the value of "op" must be equal to 29.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:2031: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:2035: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def593'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def593'>[#def593]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def594'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def594'>[#def594]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def595'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def595'>[#def595]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def596'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def596'>[#def596]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:434: <b>cond_notnull</b>: Condition "bus", taking true branch. Now the value of "bus" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:455: <b>notnull</b>: At condition "bus", the value of "bus" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qdev-monitor.c:455: <b>dead_error_condition</b>: The condition "!bus" cannot be true.</span> qemu-kvm-1.2.0/hw/qdev-monitor.c:456: <b>dead_error_line</b>: Execution cannot reach this statement "bus = sysbus_get_default();". <a name='def597'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def597'>[#def597]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:524: <b>dead_error_condition</b>: The switch value "idx & 3" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:534: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def598'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def598'>[#def598]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:513: <b>assignment</b>: Assigning: "patches" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>const</b>: At condition "patches != 0", the value of "patches" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>dead_error_condition</b>: The condition "patches != 0" cannot be true.</span> qemu-kvm-1.2.0/hw/kvmvapic.c:546: <b>dead_error_line</b>: Execution cannot reach this expression "patches != 2" inside statement "if (patches != 0 && patches...". <a name='def599'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def599'>[#def599]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:563: <b>dead_error_condition</b>: The switch value "idx & 3" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:573: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def600'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def600'>[#def600]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 37", taking false branch. Now the value of "op" is equal to 37.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 42", taking false branch. Now the value of "op" is equal to 42.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3538: <b>cond_const</b>: Condition "op != 47", taking false branch. Now the value of "op" is equal to 47.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3542: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[37,37], [42,42], [47,47]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3542: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/monitor.c:3543: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def601'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def601'>[#def601]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 124", taking false branch. Now the value of "op" is equal to 124.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 38", taking false branch. Now the value of "op" is equal to 38.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3569: <b>cond_const</b>: Condition "op != 94", taking false branch. Now the value of "op" is equal to 94.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3573: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[38,38], [94,94], [124,124]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:3573: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/monitor.c:3574: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def602'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def602'>[#def602]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8385: <b>equality_cond</b>: Jumping to case "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8386: <b>equality_cond</b>: Jumping to case "1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8400: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8389: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8403: <b>equality_cond</b>: Jumping to case "12".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8404: <b>equality_cond</b>: Jumping to case "13".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8407: <b>equality_cond</b>: Jumping to case "14".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8387: <b>equality_cond</b>: Jumping to case "2".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8388: <b>equality_cond</b>: Jumping to case "3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8392: <b>equality_cond</b>: Jumping to case "4".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8393: <b>equality_cond</b>: Jumping to case "5".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8394: <b>equality_cond</b>: Jumping to case "6".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8395: <b>equality_cond</b>: Jumping to case "7".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8398: <b>equality_cond</b>: Jumping to case "8".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8399: <b>equality_cond</b>: Jumping to case "9".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8479: <b>between</b>: When switching on "aregs", the value of "aregs" must be between 0 and 14.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:8479: <b>dead_error_condition</b>: The switch value "aregs" cannot reach the default case.</span> qemu-kvm-1.2.0/target-mips/translate.c:8505: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def603'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def603'>[#def603]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2740: <b>equality_cond</b>: Jumping to case "1342177280U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2772: <b>equality_cond</b>: Jumping to case "134217728U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2742: <b>equality_cond</b>: Jumping to case "1409286144U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2759: <b>equality_cond</b>: Jumping to case "1476395008U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2757: <b>equality_cond</b>: Jumping to case "1543503872U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2774: <b>equality_cond</b>: Jumping to case "1946157056U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2776: <b>equality_cond</b>: Jumping to case "1946157061U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2773: <b>equality_cond</b>: Jumping to case "201326592U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2775: <b>equality_cond</b>: Jumping to case "201326597U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2739: <b>equality_cond</b>: Jumping to case "268435456U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2782: <b>equality_cond</b>: Jumping to case "329U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2741: <b>equality_cond</b>: Jumping to case "335544320U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2783: <b>equality_cond</b>: Jumping to case "336U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2758: <b>equality_cond</b>: Jumping to case "402653184U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2756: <b>equality_cond</b>: Jumping to case "469762048U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2760: <b>equality_cond</b>: Jumping to case "67108864U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2751: <b>equality_cond</b>: Jumping to case "67174400U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2764: <b>equality_cond</b>: Jumping to case "67239936U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2755: <b>equality_cond</b>: Jumping to case "67305472U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2761: <b>equality_cond</b>: Jumping to case "68157440U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2762: <b>equality_cond</b>: Jumping to case "68157445U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2752: <b>equality_cond</b>: Jumping to case "68222976U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2753: <b>equality_cond</b>: Jumping to case "68222981U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2763: <b>equality_cond</b>: Jumping to case "68288512U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2754: <b>equality_cond</b>: Jumping to case "68354048U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2780: <b>equality_cond</b>: Jumping to case "8U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2781: <b>equality_cond</b>: Jumping to case "9U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2801: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[8,9], [329,329], [336,336], [67108864,67108864], [67174400,67174400], [67239936,67239936], [67305472,67305472], [68157440,68157440], [68157445,68157445], [68222976,68222976], [68222981,68222981], [68288512,68288512], [68354048,68354048], [134217728,134217728], [201326592,201326592], [201326597,201326597], [268435456,268435456], [335544320,335544320], [402653184,402653184], [469762048,469762048], [1342177280,1342177280], [1409286144,1409286144], [1476395008,1476395008], [1543503872,1543503872], [1946157056,1946157056], [1946157061,1946157061]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2801: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-mips/translate.c:2887: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def604'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def604'>[#def604]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2740: <b>equality_cond</b>: Jumping to case "1342177280U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2742: <b>equality_cond</b>: Jumping to case "1409286144U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2759: <b>equality_cond</b>: Jumping to case "1476395008U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2757: <b>equality_cond</b>: Jumping to case "1543503872U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2739: <b>equality_cond</b>: Jumping to case "268435456U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2741: <b>equality_cond</b>: Jumping to case "335544320U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2758: <b>equality_cond</b>: Jumping to case "402653184U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2756: <b>equality_cond</b>: Jumping to case "469762048U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2760: <b>equality_cond</b>: Jumping to case "67108864U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2751: <b>equality_cond</b>: Jumping to case "67174400U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2764: <b>equality_cond</b>: Jumping to case "67239936U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2755: <b>equality_cond</b>: Jumping to case "67305472U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2761: <b>equality_cond</b>: Jumping to case "68157440U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2762: <b>equality_cond</b>: Jumping to case "68157445U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2752: <b>equality_cond</b>: Jumping to case "68222976U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2753: <b>equality_cond</b>: Jumping to case "68222981U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2763: <b>equality_cond</b>: Jumping to case "68288512U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2754: <b>equality_cond</b>: Jumping to case "68354048U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2893: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[67108864,67108864], [67174400,67174400], [67239936,67239936], [67305472,67305472], [68157440,68157440], [68157445,68157445], [68222976,68222976], [68222981,68222981], [68288512,68288512], [68354048,68354048], [268435456,268435456], [335544320,335544320], [402653184,402653184], [469762048,469762048], [1342177280,1342177280], [1409286144,1409286144], [1476395008,1476395008], [1543503872,1543503872]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:2893: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-mips/translate.c:2978: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def605'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def605'>[#def605]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3609: <b>equality_cond</b>: Jumping to case "298".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3608: <b>equality_cond</b>: Jumping to case "42".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3622: <b>intervals</b>: When switching on "b >> 8", the value of "b" must be in one of the following intervals: {[42,42], [298,298]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3622: <b>dead_error_condition</b>: The switch value "b >> 8" cannot reach the default case.</span> qemu-kvm-1.2.0/target-i386/translate.c:3626: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def606'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def606'>[#def606]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3337: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3336: <b>equality_cond</b>: Jumping to case "8".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3343: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[8,8], [10,10]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3343: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3350: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def607'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def607'>[#def607]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3358: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3360: <b>equality_cond</b>: Jumping to case "25".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3369: <b>equality_cond</b>: Jumping to case "25".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3359: <b>equality_cond</b>: Jumping to case "27".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3363: <b>equality_cond</b>: Jumping to case "27".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3357: <b>equality_cond</b>: Jumping to case "9".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3382: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[9,9], [11,11], [25,25], [27,27]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3382: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3391: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def608'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def608'>[#def608]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3521: <b>equality_cond</b>: Jumping to case "128".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3522: <b>equality_cond</b>: Jumping to case "129".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3523: <b>equality_cond</b>: Jumping to case "130".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3526: <b>between</b>: When switching on "op", the value of "op" must be between 128 and 130.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3526: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3536: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def609'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def609'>[#def609]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3718: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3719: <b>equality_cond</b>: Jumping to case "13".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3717: <b>equality_cond</b>: Jumping to case "7".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3721: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[7,7], [11,11], [13,13]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3721: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3731: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def610'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def610'>[#def610]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3780: <b>equality_cond</b>: Jumping to case "10".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3779: <b>equality_cond</b>: Jumping to case "4".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3784: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[4,4], [10,10]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3784: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3793: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def611'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def611'>[#def611]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3802: <b>equality_cond</b>: Jumping to case "11".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3801: <b>equality_cond</b>: Jumping to case "5".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3806: <b>intervals</b>: When switching on "op", the value of "op" must be in one of the following intervals: {[5,5], [11,11]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:3806: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:3815: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def612'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def612'>[#def612]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def613'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def613'>[#def613]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def614'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def614'>[#def614]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6578: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6593: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6608: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6623: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6976: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6992: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7008: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7024: <b>assignment</b>: Assigning: "optype" = "BINOP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6561: <b>assignment</b>: Assigning: "optype" = "OTHEROP".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7746: <b>intervals</b>: When switching on "optype", the value of "optype" must be in one of the following intervals: {[0,0], [2,2]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:7750: <b>dead_error_condition</b>: The switch value "optype" cannot be "CMPOP".</span> qemu-kvm-1.2.0/target-mips/translate.c:7750: <b>dead_error_begin</b>: Execution cannot reach this statement "case CMPOP:". <a name='def615'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def615'>[#def615]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:587: <b>dead_error_condition</b>: The switch value "(insn >> 3) & 7" cannot reach the default case.</span> qemu-kvm-1.2.0/target-m68k/translate.c:677: <b>dead_error_line</b>: Execution cannot reach this statement "return NULL_QREG;". <a name='def616'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def616'>[#def616]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1142: <b>assignment</b>: Assigning: "op" = "(insn >> 6) & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>between</b>: When switching on "op", the value of "op" must be between 1 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1151: <b>cond_cannot_single</b>: Condition "op", taking true branch. Now the value of "op" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>cannot_single</b>: When switching on "op", the value of "op" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:1173: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/target-m68k/translate.c:1183: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def617'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def617'>[#def617]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:510: <b>dead_error_condition</b>: The switch value "(insn >> 3) & 7" cannot reach the default case.</span> qemu-kvm-1.2.0/target-m68k/translate.c:554: <b>dead_error_line</b>: Execution cannot reach this statement "return NULL_QREG;". <a name='def618'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def618'>[#def618]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def619'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def619'>[#def619]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def620'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def620'>[#def620]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:143: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:144: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def621'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def621'>[#def621]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def622'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def622'>[#def622]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def623'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def623'>[#def623]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def624'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def624'>[#def624]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:791: <b>assignment</b>: Assigning: "memory_map_mode" = "(s->gr[6] >> 2) & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:793: <b>between</b>: When switching on "memory_map_mode", the value of "memory_map_mode" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:793: <b>dead_error_condition</b>: The switch value "memory_map_mode" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/vga.c:806: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def625'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def625'>[#def625]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:851: <b>assignment</b>: Assigning: "memory_map_mode" = "(s->gr[6] >> 2) & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:853: <b>between</b>: When switching on "memory_map_mode", the value of "memory_map_mode" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:853: <b>dead_error_condition</b>: The switch value "memory_map_mode" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/vga.c:866: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def626'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def626'>[#def626]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:901: <b>assignment</b>: Assigning: "write_mode" = "s->gr[5] & 3".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:902: <b>between</b>: When switching on "write_mode", the value of "write_mode" must be between 0 and 3.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vga.c:902: <b>dead_error_condition</b>: The switch value "write_mode" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/vga.c:903: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def627'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def627'>[#def627]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def628'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def628'>[#def628]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def629'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def629'>[#def629]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8733: <b>equality_cond</b>: Jumping to case "251".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8736: <b>equality_cond</b>: Jumping to case "315".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8753: <b>intervals</b>: When switching on "num", the value of "num" must be in one of the following intervals: {[251,251], [315,315]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8753: <b>dead_error_condition</b>: The switch value "num" cannot reach the default case.</span> qemu-kvm-1.2.0/linux-user/syscall.c:8782: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def630'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def630'>[#def630]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:613: <b>assignment</b>: Assigning: "cert_count" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:616: <b>incr</b>: Incrementing "cert_count". The value of "cert_count" is now 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:616: <b>incr</b>: Incrementing "cert_count". The value of "cert_count" is now 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:619: <b>at_least</b>: At condition "cert_count == 0", the value of "cert_count" must be at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:619: <b>dead_error_condition</b>: The condition "cert_count == 0" cannot be true.</span> qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:620: <b>dead_error_begin</b>: Execution cannot reach this statement "PK11_DestroyGenericObjects(...". <a name='def631'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def631'>[#def631]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:452: <b>dead_error_condition</b>: The switch value "(tlb->tte >> 61) & 3ULL" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/mmu_helper.c:453: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def632'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def632'>[#def632]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4563: <b>equality_cond</b>: Jumping to case "136".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4564: <b>equality_cond</b>: Jumping to case "137".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4565: <b>equality_cond</b>: Jumping to case "138".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4573: <b>between</b>: When switching on "opc", the value of "opc" must be between 136 and 138.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4573: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4584: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def633'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def633'>[#def633]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4666: <b>equality_cond</b>: Jumping to case "148".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4667: <b>equality_cond</b>: Jumping to case "150".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4668: <b>equality_cond</b>: Jumping to case "151".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4673: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[148,148], [150,151]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4673: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4683: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def634'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def634'>[#def634]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4967: <b>equality_cond</b>: Jumping to case "192".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4968: <b>equality_cond</b>: Jumping to case "194".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4973: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[192,192], [194,194]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4973: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4980: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def635'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def635'>[#def635]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4984: <b>equality_cond</b>: Jumping to case "210".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4985: <b>equality_cond</b>: Jumping to case "212".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4986: <b>equality_cond</b>: Jumping to case "213".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4987: <b>equality_cond</b>: Jumping to case "214".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4988: <b>equality_cond</b>: Jumping to case "215".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4989: <b>equality_cond</b>: Jumping to case "220".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4990: <b>equality_cond</b>: Jumping to case "243".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4999: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[210,210], [212,215], [220,220], [243,243]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4999: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:5030: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def636'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def636'>[#def636]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4238: <b>equality_cond</b>: Jumping to case "74".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4239: <b>equality_cond</b>: Jumping to case "75".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4240: <b>equality_cond</b>: Jumping to case "76".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4250: <b>between</b>: When switching on "opc", the value of "opc" must be between 74 and 76.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4250: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4262: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def637'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def637'>[#def637]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4361: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4373: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4362: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4377: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4363: <b>equality_cond</b>: Jumping to case "94".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4374: <b>equality_cond</b>: Jumping to case "94".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4364: <b>equality_cond</b>: Jumping to case "95".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4378: <b>equality_cond</b>: Jumping to case "95".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4385: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[90,91], [94,95]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4385: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4398: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def638'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def638'>[#def638]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4361: <b>equality_cond</b>: Jumping to case "90".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4362: <b>equality_cond</b>: Jumping to case "91".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4363: <b>equality_cond</b>: Jumping to case "94".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4364: <b>equality_cond</b>: Jumping to case "95".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4372: <b>intervals</b>: When switching on "opc", the value of "opc" must be in one of the following intervals: {[90,91], [94,95]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:4372: <b>dead_error_condition</b>: The switch value "opc" cannot reach the default case.</span> qemu-kvm-1.2.0/target-s390x/translate.c:4381: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def639'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def639'>[#def639]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def640'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def640'>[#def640]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def641'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def641'>[#def641]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:288: <b>dead_error_condition</b>: The condition "(addr & 0UL) != 0UL" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:289: <b>dead_error_line</b>: Execution cannot reach this statement "do_unaligned_access(env, ad...". <a name='def642'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def642'>[#def642]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:170: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:171: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def643'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def643'>[#def643]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:112: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:113: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def644'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def644'>[#def644]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:165: <b>assignment</b>: Assigning: "op" = "(insn >> 7) & 0xfU".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:170: <b>between</b>: When switching on "op", the value of "op" must be between 0 and 15.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/milkymist-pfpu.c:170: <b>dead_error_condition</b>: The switch value "op" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/milkymist-pfpu.c:304: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def645'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def645'>[#def645]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/cmd646.c:135: <b>dead_error_condition</b>: The switch value "addr & 3UL" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/ide/cmd646.c:152: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def646'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def646'>[#def646]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:7977: <b>dead_error_condition</b>: The switch value "(insn >> 25) & 0xfU" cannot reach the default case.</span> qemu-kvm-1.2.0/target-arm/translate.c:8969: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def647'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def647'>[#def647]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def648'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def648'>[#def648]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:288: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:292: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_str(m, (obj ? &(...". <a name='def649'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def649'>[#def649]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:288: <b>cond_notnull</b>: Condition "obj", taking true branch. Now the value of "obj" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>notnull</b>: At condition "obj", the value of "obj" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>dead_error_condition</b>: The condition "obj" must be true.</span> qemu-kvm-1.2.0/qga/qapi-generated/qga-qapi-visit.c:297: <b>dead_error_line</b>: Execution cannot reach this expression "NULL" inside statement "visit_type_GuestIpAddressLi...". <a name='def650'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def650'>[#def650]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:313: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:314: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def651'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def651'>[#def651]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_template.h:258: <b>dead_error_condition</b>: The condition "(addr & 0U) != 0U" cannot be true.</span> qemu-kvm-1.2.0/softmmu_template.h:259: <b>dead_error_line</b>: Execution cannot reach this statement "goto do_unaligned_access;". <a name='def652'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def652'>[#def652]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/esp-pci.c:108: <b>dead_error_condition</b>: The switch value "val & 3U" cannot reach the default case.</span> qemu-kvm-1.2.0/hw/esp-pci.c:121: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def653'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def653'>[#def653]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:3874: <b>assignment</b>: Assigning: "is_data" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:4012: <b>const</b>: At condition "is_data", the value of "is_data" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:4012: <b>dead_error_condition</b>: The condition "is_data" cannot be true.</span> qemu-kvm-1.2.0/arm-dis.c:4014: <b>dead_error_begin</b>: Execution cannot reach this statement "int i;". <a name='def654'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def654'>[#def654]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2320: <b>assignment</b>: Assigning: "length" = "((given >> 8) & 3L) + 1L".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2324: <b>cond_const</b>: Condition "length > 1", taking false branch. Now the value of "length" is equal to 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2324: <b>cond_between</b>: Condition "length > 1", taking true branch. Now the value of "length" is between 2 and 4.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2327: <b>between</b>: When switching on "length", the value of "length" must be between 1 and 4.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2327: <b>dead_error_condition</b>: The switch value "length" cannot reach the default case.</span> qemu-kvm-1.2.0/arm-dis.c:2367: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def655'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def655'>[#def655]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2466: <b>assignment</b>: Assigning: "size" = "16".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2460: <b>assignment</b>: Assigning: "size" = "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2473: <b>assignment</b>: Assigning: "size" = "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2511: <b>assignment</b>: Assigning: "size" = "32".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2493: <b>assignment</b>: Assigning: "size" = "64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2499: <b>assignment</b>: Assigning: "size" = "8".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2520: <b>intervals</b>: When switching on "size", the value of "size" must be in one of the following intervals: {[8,8], [16,16], [32,32], [64,64]}.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arm-dis.c:2520: <b>dead_error_condition</b>: The switch value "size" cannot reach the default case.</span> qemu-kvm-1.2.0/arm-dis.c:2558: <b>dead_error_begin</b>: Execution cannot reach this statement "default:". <a name='def656'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def656'>[#def656]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:145: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "4".</span> qemu-kvm-1.2.0/hw/mcf_uart.c:145: <b>dead_error_begin</b>: Execution cannot reach this statement "case 4:". <a name='def657'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def657'>[#def657]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:147: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "5".</span> qemu-kvm-1.2.0/hw/mcf_uart.c:147: <b>dead_error_begin</b>: Execution cannot reach this statement "case 5:". <a name='def658'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def658'>[#def658]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:150: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "6".</span> qemu-kvm-1.2.0/hw/mcf_uart.c:150: <b>dead_error_line</b>: Execution cannot reach this statement "case 6:". <a name='def659'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def659'>[#def659]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/mcf_uart.c:151: <b>dead_error_condition</b>: The switch value "(cmd >> 4) & 3" cannot be "7".</span> qemu-kvm-1.2.0/hw/mcf_uart.c:151: <b>dead_error_begin</b>: Execution cannot reach this statement "case 7:". <a name='def660'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def660'>[#def660]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:387: <b>assignment</b>: Assigning: "lma" = "false".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:394: <b>const</b>: At condition "lma", the value of "lma" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:394: <b>dead_error_condition</b>: The condition "lma" cannot be true.</span> qemu-kvm-1.2.0/target-i386/arch_dump.c:395: <b>dead_error_line</b>: Execution cannot reach this statement "info->d_machine = 62;". <a name='def661'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def661'>[#def661]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:387: <b>assignment</b>: Assigning: "lma" = "false".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:401: <b>const</b>: At condition "lma", the value of "lma" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/arch_dump.c:401: <b>dead_error_condition</b>: The condition "lma" cannot be true.</span> qemu-kvm-1.2.0/target-i386/arch_dump.c:402: <b>dead_error_line</b>: Execution cannot reach this statement "info->d_class = 2;". <a name='def662'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def662'>[#def662]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/sparc-dis.c:3053: <b>dead_error_condition</b>: The condition "(unsigned int)((insn >> 14) & 0x1fUL) < 32U" must be true.</span> qemu-kvm-1.2.0/sparc-dis.c:3057: <b>dead_error_line</b>: Execution cannot reach this statement "(*info->fprintf_func)(strea...". <a name='def663'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def663'>[#def663]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/sparc-dis.c:3061: <b>dead_error_condition</b>: The condition "(unsigned int)((insn >> 25) & 0x1fUL) < 32U" must be true.</span> qemu-kvm-1.2.0/sparc-dis.c:3065: <b>dead_error_line</b>: Execution cannot reach this statement "(*info->fprintf_func)(strea...". <a name='def664'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def664'>[#def664]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/arm-semi.c:226: <b>dead_error_condition</b>: The condition "({...})" cannot be true.</span> qemu-kvm-1.2.0/target-arm/arm-semi.c:228: <b>dead_error_line</b>: Execution cannot reach this statement "return 4294967295U;". <a name='def665'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def665'>[#def665]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:178: <b>assignment</b>: Assigning: "nextchr" = "-1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:215: <b>assignment</b>: Assigning: "nextchr" = "-1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>const</b>: At condition "nextchr == -1", the value of "nextchr" must be equal to -1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>dead_error_condition</b>: The condition "nextchr == -1" must be true.</span> qemu-kvm-1.2.0/ui/curses.c:184: <b>dead_error_begin</b>: Execution cannot reach this statement "chr = nextchr;". <a name='def666'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def666'>[#def666]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:120: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> qemu-kvm-1.2.0/hw/ppce500_pci.c:120: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". <a name='def667'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def667'>[#def667]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:142: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> qemu-kvm-1.2.0/hw/ppce500_pci.c:142: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". <a name='def668'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def668'>[#def668]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:191: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> qemu-kvm-1.2.0/hw/ppce500_pci.c:191: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". <a name='def669'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def669'>[#def669]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppce500_pci.c:213: <b>dead_error_condition</b>: The switch value "addr & 0xcUL" cannot be "16UL".</span> qemu-kvm-1.2.0/hw/ppce500_pci.c:213: <b>dead_error_begin</b>: Execution cannot reach this statement "case 16UL:". <a name='def670'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def670'>[#def670]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:73: <b>cond_at_most</b>: Condition "data < 8", taking true branch. Now the value of "data" is at most 7.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:83: <b>equality_cond</b>: Jumping to case "2".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:84: <b>const</b>: At condition "data & 0x40", the value of "data" must be equal to 2.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ds1338.c:84: <b>dead_error_condition</b>: The condition "data & 0x40" cannot be true.</span> qemu-kvm-1.2.0/hw/ds1338.c:85: <b>dead_error_line</b>: Execution cannot reach this statement "if (data & 0x20){ data = ...". <a name='def671'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def671'>[#def671]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:253: <b>cond_notnull</b>: Condition "reader != NULL", taking true branch. Now the value of "reader" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>notnull</b>: At condition "reader", the value of "reader" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>dead_error_condition</b>: The condition "reader" must be true.</span> qemu-kvm-1.2.0/libcacard/vscclient.c:255: <b>dead_error_line</b>: Execution cannot reach this expression ""invalid reader"" inside statement "printf("insert %s, returned...". <a name='def672'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def672'>[#def672]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:266: <b>cond_notnull</b>: Condition "reader != NULL", taking true branch. Now the value of "reader" is not NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>notnull</b>: At condition "reader", the value of "reader" cannot be NULL.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>dead_error_condition</b>: The condition "reader" must be true.</span> qemu-kvm-1.2.0/libcacard/vscclient.c:268: <b>dead_error_line</b>: Execution cannot reach this expression ""invalid reader"" inside statement "printf("remove %s, returned...". <a name='def673'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def673'>[#def673]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:740: <b>cond_const</b>: Condition "bits != 256", taking false branch. Now the value of "bits" is equal to 256.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:798: <b>const</b>: At condition "bits == 256", the value of "bits" must be equal to 256.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:798: <b>dead_error_condition</b>: The condition "bits == 256" must be true.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/aes.c:799: <b>dead_error_condition</b>: The condition "1" must be true.</span> qemu-kvm-1.2.0/aes.c:826: <b>dead_error_line</b>: Execution cannot reach this statement "return 0;". <a name='def674'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def674'>[#def674]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_at_least</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:195: <b>cond_at_least</b>: Condition "quot > 65535U", taking true branch. Now the value of "quot" is at least 65536.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_at_least</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is at least 65536.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:195: <b>cond_at_most</b>: Condition "quot > 65535U", taking false branch. Now the value of "quot" is at most 65535.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_between</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" is between 1 and 65535.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>at_least</b>: At condition "(int32_t)quot < 0", the value of "quot" must be at least 1.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:197: <b>cond_cannot_single</b>: Condition "quot == 0U", taking false branch. Now the value of "quot" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>cannot_single</b>: At condition "(int32_t)quot < 0", the value of "quot" cannot be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/op_helper.c:199: <b>dead_error_condition</b>: The condition "(int32_t)quot < 0" cannot be true.</span> qemu-kvm-1.2.0/target-m68k/op_helper.c:200: <b>dead_error_line</b>: Execution cannot reach this statement "flags |= 8U;". <a name='def675'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def675'>[#def675]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:616: <b>assignment</b>: Assigning: "persistent" = "0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:626: <b>const</b>: At condition "persistent", the value of "persistent" must be equal to 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:626: <b>dead_error_condition</b>: The condition "persistent" cannot be true.</span> qemu-kvm-1.2.0/linux-user/flatload.c:627: <b>dead_error_line</b>: Execution cannot reach this statement "continue;". <a name='def676'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def676'>[#def676]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:741: <b>dead_error_condition</b>: The switch value "(env->dtlb[i].tte >> 61) & 3ULL" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/mmu_helper.c:742: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def677'/><b>Error: <span style='background: #C0FF00;'>DEADCODE</span> (CWE-561):</b> <a href ='#def677'>[#def677]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/mmu_helper.c:778: <b>dead_error_condition</b>: The switch value "(env->itlb[i].tte >> 61) & 3ULL" cannot reach the default case.</span> qemu-kvm-1.2.0/target-sparc/mmu_helper.c:779: <b>dead_error_line</b>: Execution cannot reach this statement "default:". <a name='def678'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def678'>[#def678]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:626: <b>assign_zero</b>: Assigning: "ioeventfds" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>cond_true</b>: Condition "fr < as->current_map.ranges + as->current_map.nr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>cond_true</b>: Condition "i < fr->mr->ioeventfd_nb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:635: <b>cond_false</b>: Condition "addrrange_intersects(fr->addr, tmp)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:641: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:631: <b>cond_false</b>: Condition "i < fr->mr->ioeventfd_nb", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:642: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:643: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:630: <b>cond_false</b>: Condition "fr < as->current_map.ranges + as->current_map.nr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:643: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:645: <b>var_deref_model</b>: Passing null pointer "ioeventfds" to function "address_space_add_del_ioeventfds(AddressSpace *, MemoryRegionIoeventfd *, unsigned int, MemoryRegionIoeventfd *, unsigned int)", which dereferences it.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:588:5: <b>cond_true</b>: Condition "iold < fds_old_nb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:589:9: <b>cond_true</b>: Condition "iold < fds_old_nb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/memory.c:589:9: <b>cond_false</b>: Condition "inew == fds_new_nb", taking false branch</span> qemu-kvm-1.2.0/memory.c:589:9: <b>deref_parm</b>: Directly dereferencing parameter "fds_new". <a name='def679'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def679'>[#def679]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:285: <b>cond_false</b>: Condition "req->dev", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:287: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:285: <b>var_compare_op</b>: Comparing "req->dev" to null implies that "req->dev" might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:287: <b>cond_true</b>: Condition "req->bus->unit_attention.key == 6", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:288: <b>var_deref_model</b>: Passing "req" to function "scsi_req_build_sense(SCSIRequest *, SCSISense)", which dereferences null "req->dev".</span> qemu-kvm-1.2.0/hw/scsi-bus.c:664:5: <b>deref_parm</b>: Directly dereferencing parameter "req->dev". <a name='def680'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def680'>[#def680]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:464: <b>assign_zero</b>: Assigning: "buf" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:465: <b>cond_true</b>: Condition "virtqueue_pop(vq, &elem)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:473: <b>cond_false</b>: Condition "cur_len > len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:478: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/virtio-serial-bus.c:479: <b>var_deref_model</b>: Passing null pointer "buf" to function "iov_to_buf(struct iovec const *, unsigned int const, size_t, void *, size_t)", which dereferences it. <span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:53:5: <b>cond_true</b>: Condition "offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:53:5: <b>cond_true</b>: Condition "i < iov_cnt", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:54:9: <b>cond_true</b>: Condition "offset < (iov + i).iov_len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/iov.c:56:13: <b>deref_parm_field_in_call</b>: Function "memcpy(void * restrict, void const * restrict, size_t)" dereferences an offset off "buf".</span> <a name='def681'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def681'>[#def681]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:420: <b>assign_zero</b>: Assigning: "refcount_block" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:428: <b>cond_false</b>: Condition "length < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:430: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:430: <b>cond_false</b>: Condition "length == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:432: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:434: <b>cond_true</b>: Condition "addend < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:441: <b>cond_true</b>: Condition "cluster_offset <= last", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:450: <b>cond_false</b>: Condition "table_index != old_table_index", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:463: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block/qcow2-refcount.c:472: <b>var_deref_op</b>: Dereferencing null pointer "refcount_block". <a name='def682'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def682'>[#def682]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1047: <b>cond_true</b>: Condition "l1_size2 == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1048: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1049: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1056: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:1059: <b>cond_true</b>: Condition "i < l1_size", taking true branch</span> qemu-kvm-1.2.0/block/qcow2-refcount.c:1060: <b>var_deref_op</b>: Dereferencing null pointer "l1_table". <a name='def683'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def683'>[#def683]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1009"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2259: <b>switch_case</b>: Reached case "1009"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2260: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_advqueue(EHCIQueue *)", which dereferences it.</span> qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:1963:5: <b>deref_parm</b>: Directly dereferencing parameter "q". <a name='def684'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def684'>[#def684]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1011"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2271: <b>switch_case</b>: Reached case "1011"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2272: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_execute(EHCIQueue *)", which dereferences it.</span> qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2100:19: <b>deref_parm</b>: Directly dereferencing parameter "q". <a name='def685'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def685'>[#def685]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1010"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2263: <b>switch_case</b>: Reached case "1010"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2264: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_fetchqtd(EHCIQueue *)", which dereferences it.</span> qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:1992:5: <b>deref_parm</b>: Directly dereferencing parameter "q". <a name='def686'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def686'>[#def686]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2228: <b>assign_zero</b>: Assigning: "q" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2232: <b>switch</b>: Switch case value "1013"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2267: <b>switch_case</b>: Reached case "1013"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2268: <b>var_deref_model</b>: Passing null pointer "q" to function "ehci_state_horizqh(EHCIQueue *)", which dereferences it.</span> qemu-kvm-1.2.0/hw/usb/hcd-ehci.c:2054:5: <b>deref_parm</b>: Directly dereferencing parameter "q". <a name='def687'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def687'>[#def687]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1740: <b>cond_false</b>: Condition "class_id == 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1741: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num != bus_num", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1747: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num != bus_num", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_true</b>: Condition "f->port != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_true</b>: Condition "port == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>var_compare_op</b>: Comparing "port" to null implies that "port" might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1753: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_true</b>: Condition "f->bus_num > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num != bus_num", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_false</b>: Condition "f->port != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1754: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id != vendor_id", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1757: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1779: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1743: <b>cond_true</b>: Condition "s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1746: <b>cond_false</b>: Condition "f->bus_num > 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1748: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_true</b>: Condition "f->addr > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1749: <b>cond_false</b>: Condition "f->addr != addr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1752: <b>cond_false</b>: Condition "f->port != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1754: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_true</b>: Condition "f->vendor_id > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1756: <b>cond_false</b>: Condition "f->vendor_id != vendor_id", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1758: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1760: <b>cond_true</b>: Condition "f->product_id > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1760: <b>cond_false</b>: Condition "f->product_id != product_id", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1765: <b>cond_false</b>: Condition "s->errcount >= 3", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1767: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1770: <b>cond_false</b>: Condition "s->fd != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1772: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/usb/host-linux.c:1775: <b>var_deref_model</b>: Passing null pointer "port" to function "usb_host_open(USBHostDevice *, int, int, char const *, char const *, int)", which dereferences it. <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1293:5: <b>cond_false</b>: Condition "dev->fd != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1295:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1298:5: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1300:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1305:5: <b>deref_parm_in_call</b>: Function "strcpy(char * restrict, char const * restrict)" dereferences "port".</span> <a name='def688'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def688'>[#def688]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>cond_true</b>: Condition "index < s->mapping.next", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>cond_false</b>: Condition "mapping = array_get(&s->mapping, index)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1962: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1957: <b>var_compare_op</b>: Comparing "mapping" to null implies that "mapping" might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:1963: <b>cond_false</b>: Condition "index >= s->mapping.next", taking false branch</span> qemu-kvm-1.2.0/block/vvfat.c:1963: <b>var_deref_op</b>: Dereferencing null pointer "mapping". <a name='def689'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def689'>[#def689]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_true</b>: Condition "*args == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1146: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>cond_true</b>: Condition "*args != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1143: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_false</b>: Condition "*args == ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1147: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1150: <b>cond_true</b>: Condition "__coverity_strncmp(args, "soft=", 5) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1163: <b>cond_false</b>: Condition "*args != '('", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1165: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1171: <b>cond_true</b>: Condition "type_params_length < 99UL /* sizeof (type_str) - 1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1178: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1180: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1182: <b>cond_true</b>: Condition "opts->vreader_count >= reader_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1186: <b>cond_false</b>: Condition "vreaderOpt == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1188: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>cond_true</b>: Condition "i < count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1205: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1200: <b>cond_false</b>: Condition "i < count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1205: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1206: <b>cond_true</b>: Condition "*args == ')'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1211: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1247: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1248: <b>cond_true</b>: Condition "*args != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1143: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1145: <b>cond_false</b>: Condition "*args == ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1147: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1150: <b>cond_true</b>: Condition "__coverity_strncmp(args, "soft=", 5) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1160: <b>assign_zero</b>: Assigning: "vreaderOpt" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1163: <b>cond_false</b>: Condition "*args != '('", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1165: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1168: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1169: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1170: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1171: <b>cond_true</b>: Condition "type_params_length < 99UL /* sizeof (type_str) - 1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>cond_false</b>: Condition "*args == ')'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1176: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1178: <b>cond_false</b>: Condition "*args == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1180: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1182: <b>cond_false</b>: Condition "opts->vreader_count >= reader_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1189: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1191: <b>alias_transfer</b>: Assigning: "vreaderOpt" = "vreaderOpt + opts->vreader_count".</span> qemu-kvm-1.2.0/libcacard/vcard_emul_nss.c:1192: <b>var_deref_op</b>: Dereferencing null pointer "vreaderOpt". <a name='def690'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def690'>[#def690]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "128"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:444: <b>switch_case</b>: Reached case "128"</span> qemu-kvm-1.2.0/hw/omap_intc.c:445: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def691'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def691'>[#def691]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "132"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:447: <b>switch_case</b>: Reached case "132"</span> qemu-kvm-1.2.0/hw/omap_intc.c:448: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def692'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def692'>[#def692]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "144"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:454: <b>switch_case</b>: Reached case "144"</span> qemu-kvm-1.2.0/hw/omap_intc.c:455: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def693'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def693'>[#def693]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "152"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:460: <b>switch_case</b>: Reached case "152"</span> qemu-kvm-1.2.0/hw/omap_intc.c:461: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def694'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def694'>[#def694]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:405: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:407: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:416: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:418: <b>switch</b>: Switch case value "156"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:463: <b>switch_case</b>: Reached case "156"</span> qemu-kvm-1.2.0/hw/omap_intc.c:464: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def695'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def695'>[#def695]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "132"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:535: <b>switch_case</b>: Reached case "132"</span> qemu-kvm-1.2.0/hw/omap_intc.c:536: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def696'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def696'>[#def696]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "136"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:541: <b>switch_case</b>: Reached case "136"</span> qemu-kvm-1.2.0/hw/omap_intc.c:542: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def697'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def697'>[#def697]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "140"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:547: <b>switch_case</b>: Reached case "140"</span> qemu-kvm-1.2.0/hw/omap_intc.c:548: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def698'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def698'>[#def698]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "144"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:551: <b>switch_case</b>: Reached case "144"</span> qemu-kvm-1.2.0/hw/omap_intc.c:552: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def699'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def699'>[#def699]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:486: <b>assign_zero</b>: Assigning: "bank" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:488: <b>cond_false</b>: Condition "(offset & 0xf80) == 0x80", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:497: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:499: <b>switch</b>: Switch case value "148"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_intc.c:557: <b>switch_case</b>: Reached case "148"</span> qemu-kvm-1.2.0/hw/omap_intc.c:558: <b>var_deref_op</b>: Dereferencing null pointer "bank". <a name='def700'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def700'>[#def700]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:659: <b>cond_true</b>: Condition "s->sizearg == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:660: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:663: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:669: <b>cond_true</b>: Condition "ivshmem_has_feature(s, 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:669: <b>cond_false</b>: Condition "!ivshmem_has_feature(s, 1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:676: <b>cond_true</b>: Condition "s->role", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:677: <b>cond_true</b>: Condition "__coverity_strncmp(s->role, "peer", 5) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:679: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:684: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:685: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:687: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:689: <b>cond_true</b>: Condition "s->role_val == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:711: <b>cond_true</b>: Condition "s->server_chr != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:711: <b>cond_false</b>: Condition "__coverity_strncmp(s->server_chr->filename, "unix:", 5) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:741: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:745: <b>cond_true</b>: Condition "s->shmobj == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ivshmem.c:745: <b>var_compare_op</b>: Comparing "s->shmobj" to null implies that "s->shmobj" might be null.</span> qemu-kvm-1.2.0/hw/ivshmem.c:753: <b>var_deref_model</b>: Passing null pointer "s->shmobj" to function "shm_open(char const *, int, mode_t)", which dereferences it. <a name='def701'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def701'>[#def701]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3538: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3540: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3544: <b>cond_true</b>: Condition "intel_syntax == -1 /* (char)-1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3545: <b>cond_false</b>: Condition "info->mach == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3545: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 3", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_false</b>: Condition "info->mach == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3548: <b>cond_true</b>: Condition "info->mach == 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3552: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3556: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>cond_true</b>: Condition "p != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3560: <b>cond_true</b>: Condition "__coverity_strncmp(p, "x86-64", 6) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3564: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3608: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3611: <b>cond_false</b>: Condition "p != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3612: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3613: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3558: <b>cond_false</b>: Condition "p != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3613: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3615: <b>cond_true</b>: Condition "intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3628: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3642: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_true</b>: Condition "i < 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_true</b>: Condition "i < 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3653: <b>cond_false</b>: Condition "i < 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3657: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3664: <b>cond_false</b>: Condition "_setjmp(priv.bailout) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3687: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3696: <b>cond_true</b>: Condition "*codep == 98", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_false</b>: Condition "prefixes & 0x800", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_true</b>: Condition "rex", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3698: <b>cond_false</b>: Condition "rex_used", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3711: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3714: <b>cond_false</b>: Condition "*codep == 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3748: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3754: <b>cond_false</b>: Condition "*codep == 144", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3759: <b>cond_true</b>: Condition "!uses_REPZ_prefix", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3759: <b>cond_true</b>: Condition "prefixes & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3764: <b>cond_true</b>: Condition "!uses_REPNZ_prefix", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3764: <b>cond_true</b>: Condition "prefixes & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3770: <b>cond_true</b>: Condition "!uses_LOCK_prefix", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3770: <b>cond_true</b>: Condition "prefixes & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3776: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3779: <b>cond_true</b>: Condition "dp->op[2].bytemode != 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3781: <b>cond_false</b>: Condition "sizeflag & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3781: <b>cond_true</b>: Condition "address_mode == mode_64bit", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3782: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3784: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3789: <b>cond_true</b>: Condition "!uses_DATA_prefix", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3789: <b>cond_true</b>: Condition "prefixes & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_true</b>: Condition "dp->op[2].bytemode == 9", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_true</b>: Condition "dp->op[0].bytemode == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3792: <b>cond_false</b>: Condition "!intel_syntax", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3801: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3804: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3804: <b>cond_true</b>: Condition "dp->op[0].bytemode == 5", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3810: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3817: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3819: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3819: <b>cond_false</b>: Condition "dp->op[0].bytemode == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3824: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3826: <b>cond_true</b>: Condition "dp->name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3826: <b>var_compare_op</b>: Comparing "dp->name" to null implies that "dp->name" might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3828: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3861: <b>switch_default</b>: Reached default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3863: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:3864: <b>switch_end</b>: Reached end of switch</span> qemu-kvm-1.2.0/i386-dis.c:3867: <b>var_deref_model</b>: Passing null pointer "dp->name" to function "putop(char const *, int)", which dereferences it. <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4340:8: <b>var_assign_parm</b>: Assigning: "p" = "template".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:4340:3: <b>deref_var</b>: Dereferencing "p" (which is a copy of "template").</span> <a name='def702'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def702'>[#def702]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:738: <b>cond_true</b>: Condition "l1_table_offset != s->l1_table_offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:739: <b>cond_false</b>: Condition "l1_size2 != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:741: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:742: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:745: <b>cond_false</b>: Condition "bdrv_pread(bs->file, l1_table_offset, l1_table, l1_size2) != l1_size2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:750: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:752: <b>cond_true</b>: Condition "i < l1_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:753: <b>var_deref_model</b>: Passing null pointer "l1_table + i" to function "be64_to_cpus(uint64_t *)", which dereferences it.</span> qemu-kvm-1.2.0/bswap.h:130:1: <b>deref_parm</b>: Directly dereferencing parameter "p". <a name='def703'/><b>Error: <span style='background: #C0FF00;'>FORWARD_NULL</span> (CWE-476):</b> <a href ='#def703'>[#def703]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:738: <b>cond_true</b>: Condition "l1_table_offset != s->l1_table_offset", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:739: <b>cond_false</b>: Condition "l1_size2 != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:741: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qcow2-refcount.c:742: <b>assign_zero</b>: Assigning: "l1_table" = "NULL".</span> qemu-kvm-1.2.0/block/qcow2-refcount.c:745: <b>var_deref_model</b>: Passing null pointer "l1_table" to function "bdrv_pread(BlockDriverState *, int64_t, void *, int)", which dereferences it. <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1707:5: <b>cond_true</b>: Condition "len > count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1710:5: <b>cond_true</b>: Condition "len > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1711:9: <b>cond_false</b>: Condition "(ret = bdrv_read(bs, sector_num, tmp_buf, 1)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1712:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1713:9: <b>deref_parm_in_call</b>: Function "memcpy(void * restrict, void const * restrict, size_t)" dereferences "buf".</span> <a name='def704'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def704'>[#def704]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3623: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3625: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block.c:3623: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. <a name='def705'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def705'>[#def705]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:389: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:391: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block.c:389: <b>loop_condition</b>: If "cco.ret == 2147483647" is initially true then it will remain true. <a name='def706'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def706'>[#def706]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1626: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:1628: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block.c:1626: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. <a name='def707'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def707'>[#def707]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3684: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3686: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block.c:3684: <b>loop_condition</b>: If "rwco.ret == 2147483647" is initially true then it will remain true. <a name='def708'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def708'>[#def708]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:298: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:300: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/qemu-io.c:298: <b>loop_condition</b>: If "async_ret == 2147483647" is initially true then it will remain true. <a name='def709'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def709'>[#def709]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:312: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-io.c:314: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/qemu-io.c:312: <b>loop_condition</b>: If "async_ret == 2147483647" is initially true then it will remain true. <a name='def710'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def710'>[#def710]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:270: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:272: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block/qed-table.c:270: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. <a name='def711'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def711'>[#def711]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:197: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:199: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block/qed-table.c:197: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. <a name='def712'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def712'>[#def712]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:292: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:294: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block/qed-table.c:292: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. <a name='def713'/><b>Error: <span style='background: #C0FF00;'>INFINITE_LOOP</span>:</b> <a href ='#def713'>[#def713]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:176: <b>loop_top</b>: Top of the loop.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/qed-table.c:178: <b>loop_bottom</b>: Bottom of the loop.</span> qemu-kvm-1.2.0/block/qed-table.c:176: <b>loop_condition</b>: If "ret == -115" is initially true then it will remain true. <a name='def714'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def714'>[#def714]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1712: <b>unterminated_case</b>: This case (value 16) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/omap_dma.c:1714: <b>fallthrough</b>: The above case falls through to this one. <a name='def715'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def715'>[#def715]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1710: <b>unterminated_case</b>: This case (value 20) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/omap_dma.c:1712: <b>fallthrough</b>: The above case falls through to this one. <a name='def716'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def716'>[#def716]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1721: <b>unterminated_case</b>: This case (value 32) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/omap_dma.c:1723: <b>fallthrough</b>: The above case falls through to this one. <a name='def717'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def717'>[#def717]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_dma.c:1719: <b>unterminated_case</b>: This case (value 36) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/omap_dma.c:1721: <b>fallthrough</b>: The above case falls through to this one. <a name='def718'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def718'>[#def718]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/translate.c:4067: <b>unterminated_case</b>: This case (value 46) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/target-sparc/translate.c:4073: <b>fallthrough</b>: The above case falls through to this one. <a name='def719'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def719'>[#def719]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap1.c:634: <b>unterminated_case</b>: This case (value 44) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/omap1.c:636: <b>fallthrough</b>: The above case falls through to this one. <a name='def720'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def720'>[#def720]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:571: <b>unterminated_case</b>: This case (value 2) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/qemu-ga.c:576: <b>fallthrough</b>: The above case falls through to this one. <a name='def721'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def721'>[#def721]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cirrus_vga.c:1308: <b>unterminated_case</b>: This case (value 7) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/cirrus_vga.c:1310: <b>fallthrough</b>: The above case falls through to this one. <a name='def722'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def722'>[#def722]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pflash_cfi02.c:145: <b>unterminated_default</b>: The default case is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/pflash_cfi02.c:150: <b>fallthrough</b>: The above case falls through to this one. <a name='def723'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def723'>[#def723]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/stellaris.c:182: <b>unterminated_case</b>: This case (value 72) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/stellaris.c:185: <b>fallthrough</b>: The above case falls through to this one. <a name='def724'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def724'>[#def724]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:4406: <b>unterminated_case</b>: This case (value 130) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/target-i386/translate.c:4409: <b>fallthrough</b>: The above case falls through to this one. <a name='def725'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def725'>[#def725]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7766: <b>unterminated_case</b>: This case (value 271) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/target-i386/translate.c:7769: <b>fallthrough</b>: The above case falls through to this one. <a name='def726'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def726'>[#def726]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pxa2xx.c:414: <b>unterminated_case</b>: This case (value 100) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/pxa2xx.c:418: <b>fallthrough</b>: The above case falls through to this one. <a name='def727'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def727'>[#def727]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:3793: <b>unterminated_case</b>: This case (value 312) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/target-i386/translate.c:3796: <b>fallthrough</b>: The above case falls through to this one. <a name='def728'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def728'>[#def728]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12282: <b>unterminated_case</b>: This case (value 1155530752) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/target-mips/translate.c:12284: <b>fallthrough</b>: The above case falls through to this one. <a name='def729'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def729'>[#def729]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:282: <b>unterminated_case</b>: This case (value 17) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/twl92230.c:283: <b>fallthrough</b>: The above case falls through to this one. <a name='def730'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def730'>[#def730]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:388: <b>unterminated_case</b>: This case (value 56) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/twl92230.c:389: <b>fallthrough</b>: The above case falls through to this one. <a name='def731'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def731'>[#def731]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/twl92230.c:489: <b>unterminated_case</b>: This case (value 19) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/twl92230.c:490: <b>fallthrough</b>: The above case falls through to this one. <a name='def732'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def732'>[#def732]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:873: <b>unterminated_case</b>: This case (value 10) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/scsi-bus.c:878: <b>fallthrough</b>: The above case falls through to this one. <a name='def733'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def733'>[#def733]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:887: <b>unterminated_case</b>: This case (value 15) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/scsi-bus.c:892: <b>fallthrough</b>: The above case falls through to this one. <a name='def734'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def734'>[#def734]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cadence_ttc.c:341: <b>unterminated_case</b>: This case (value 56) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/cadence_ttc.c:344: <b>fallthrough</b>: The above case falls through to this one. <a name='def735'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def735'>[#def735]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/cadence_ttc.c:346: <b>unterminated_case</b>: This case (value 68) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/cadence_ttc.c:349: <b>fallthrough</b>: The above case falls through to this one. <a name='def736'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def736'>[#def736]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/m68k-dis.c:1627: <b>unterminated_case</b>: This case (value 88) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/m68k-dis.c:1629: <b>fallthrough</b>: The above case falls through to this one. <a name='def737'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def737'>[#def737]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/hid.c:168: <b>unterminated_case</b>: This case (value 224) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/hid.c:173: <b>fallthrough</b>: The above case falls through to this one. <a name='def738'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def738'>[#def738]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/hid.c:173: <b>unterminated_case</b>: This case (value 231) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/hid.c:178: <b>fallthrough</b>: The above case falls through to this one. <a name='def739'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def739'>[#def739]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/jazz_led.c:164: <b>unterminated_case</b>: This case (value 16) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/jazz_led.c:167: <b>fallthrough</b>: The above case falls through to this one. <a name='def740'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def740'>[#def740]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/sh_timer.c:73: <b>unterminated_case</b>: This case (value 3) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/sh_timer.c:76: <b>fallthrough</b>: The above case falls through to this one. <a name='def741'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def741'>[#def741]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-ohci.c:1704: <b>unterminated_case</b>: This case (value 24) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/usb/hcd-ohci.c:1707: <b>fallthrough</b>: The above case falls through to this one. <a name='def742'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def742'>[#def742]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/es1370.c:540: <b>unterminated_case</b>: This case (value 40) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/es1370.c:542: <b>fallthrough</b>: The above case falls through to this one. <a name='def743'/><b>Error: <span style='background: #C0FF00;'>MISSING_BREAK</span> (CWE-484):</b> <a href ='#def743'>[#def743]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/es1370.c:538: <b>unterminated_case</b>: This case (value 44) is not terminated by a 'break' statement.</span> qemu-kvm-1.2.0/hw/es1370.c:540: <b>fallthrough</b>: The above case falls through to this one. <a name='def744'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def744'>[#def744]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1113: <b>missing_lock</b>: Accessing "d->current_async" without holding lock "QemuMutex.lock". Elsewhere, "d->current_async" is accessed with "QemuMutex.lock" held 4 out of 5 times.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:834: <b>example_lock</b>: Locking "QemuMutex.lock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:836: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1500: <b>example_lock</b>: Locking "QemuMutex.lock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1507: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1650: <b>example_lock</b>: Locking "QemuMutex.lock".</span> qemu-kvm-1.2.0/hw/qxl.c:1651: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held. <a name='def745'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def745'>[#def745]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:436: <b>missing_lock</b>: Accessing "aiocb->ret" without holding lock "lock". Elsewhere, "aiocb->ret" is accessed with "lock" held 3 out of 3 times.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:376: <b>example_lock</b>: Locking "lock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:377: <b>example_access</b>: "qemu_paiocb.ret" is accessed with lock "lock" held.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/posix-aio-compat.c:571: <b>example_lock</b>: Locking "lock".</span> qemu-kvm-1.2.0/posix-aio-compat.c:574: <b>example_access</b>: "qemu_paiocb.ret" is accessed with lock "lock" held. <a name='def746'/><b>Error: <span style='background: #C0FF00;'>MISSING_LOCK</span> (CWE-366):</b> <a href ='#def746'>[#def746]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1923: <b>missing_lock</b>: Accessing "qxl->current_async" without holding lock "QemuMutex.lock". Elsewhere, "qxl->current_async" is accessed with "QemuMutex.lock" held 4 out of 5 times.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:834: <b>example_lock</b>: Locking "QemuMutex.lock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:836: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1500: <b>example_lock</b>: Locking "QemuMutex.lock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1507: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/qxl.c:1650: <b>example_lock</b>: Locking "QemuMutex.lock".</span> qemu-kvm-1.2.0/hw/qxl.c:1651: <b>example_access</b>: "PCIQXLDevice.current_async" is accessed with lock "QemuMutex.lock" held. <a name='def747'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def747'>[#def747]</a> /tmp/tmp1Mua9_.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def748'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def748'>[#def748]</a> /tmp/tmpmaaBfZ.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def749'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def749'>[#def749]</a> /tmp/tmpxPCDO7.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def750'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def750'>[#def750]</a> /tmp/tmp3md0Bm.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def751'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def751'>[#def751]</a> /tmp/tmpVT2CXq.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def752'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def752'>[#def752]</a> /tmp/tmpC9diCp.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def753'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def753'>[#def753]</a> /tmp/tmp73vcGp.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def754'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def754'>[#def754]</a> /tmp/tmpyrOepY.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def755'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def755'>[#def755]</a> /tmp/tmplmBPNf.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def756'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def756'>[#def756]</a> /tmp/tmpud3PK9.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def757'/><b>Error: <span style='background: #C0FF00;'>MISSING_RETURN</span>:</b> <a href ='#def757'>[#def757]</a> /tmp/tmp6xy3SA.c:1: <b>missing_return</b>: Arriving at the end of a function without returning a value. <a name='def758'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def758'>[#def758]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:974: <b>cond_true</b>: Condition "__coverity_strcmp(protocol, "spice") == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:975: <b>negative_return_fn</b>: Function "monitor_get_fd(mon, fdname)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2391:5: <b>cond_true</b>: Condition "monfd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2394:9: <b>cond_true</b>: Condition "__coverity_strcmp(monfd->name, fdname) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2395:13: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2391:5: <b>cond_false</b>: Condition "monfd", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:2408:5: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:975: <b>var_assign</b>: Assigning: signed variable "fd" = "monitor_get_fd(Monitor *, char const *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:978: <b>cond_false</b>: Condition "!using_spice", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:982: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:983: <b>cond_true</b>: Condition "qemu_spice_display_add_client(fd, skipauth, tls) < 0", taking true branch</span> qemu-kvm-1.2.0/monitor.c:984: <b>negative_returns</b>: "fd" is passed to a parameter that cannot be negative. <a name='def759'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def759'>[#def759]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7902: <b>cond_true</b>: Condition "flags & (4UL /* 1 << 2 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7903: <b>cond_true</b>: Condition "dc->cpl == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7904: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7906: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "dc->tf", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "env->singlestep_enabled", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_false</b>: Condition "flags & (8UL /* 1 << 3 */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7917: <b>cond_true</b>: Condition "flags & (4UL /* 1 << 2 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7947: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7950: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7954: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7955: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7955: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7956: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7957: <b>cond_true</b>: Condition "bp->pc == pc_ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7957: <b>cond_false</b>: Condition "bp->flags & 0x20", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7960: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7962: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7964: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7966: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/translate.c:7970: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-i386/translate.c:7971: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def760'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def760'>[#def760]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:10626: <b>negative_returns</b>: Passing negative constant "-1" to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6564:5: <b>switch</b>: Switch case value "OPC_ADD_S"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6565:10: <b>switch_case</b>: Reached case "OPC_ADD_S"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:6571:13: <b>index</b>: Function "gen_load_fpr32(TCGv_i32, int)" uses "ft" as an array index.</span> qemu-kvm-1.2.0/target-mips/translate.c:666:5: <b>index</b>: Indexing "NULL->active_fpu.fpr" with "reg". <a name='def761'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def761'>[#def761]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:577: <b>cond_true</b>: Condition "rom->path == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:582: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:586: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:588: <b>cond_true</b>: Condition "fw_dir", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:593: <b>negative_return_fn</b>: Function "lseek(fd, 0L, 2)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:593: <b>var_assign</b>: Assigning: unsigned variable "rom->romsize" = "lseek(int, __off64_t, int)".</span> qemu-kvm-1.2.0/hw/loader.c:596: <b>negative_returns</b>: "rom->romsize" is passed to a parameter that cannot be negative. <a name='def762'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def762'>[#def762]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:77: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:78: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:79: <b>negative_return_fn</b>: Function "lseek(fd, 0L, 2)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:79: <b>var_assign</b>: Assigning: signed variable "size" = "lseek(int, __off64_t, int)".</span> qemu-kvm-1.2.0/hw/loader.c:81: <b>negative_returns</b>: "size" is passed to a parameter that cannot be negative. <a name='def763'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def763'>[#def763]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2569: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2576: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2585: <b>cond_true</b>: Condition "tb->flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2590: <b>cond_true</b>: Condition "tb->flags & 16", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2591: <b>cond_true</b>: Condition "tb->flags & 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2596: <b>cond_true</b>: Condition "dc.icount", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2602: <b>cond_true</b>: Condition "env->singlestep_enabled", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2602: <b>cond_true</b>: Condition "env->exception_taken", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2611: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2613: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-xtensa/translate.c:2618: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-xtensa/translate.c:2619: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def764'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def764'>[#def764]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:839: <b>cond_false</b>: Condition "addr & 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:840: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:843: <b>switch</b>: Switch case value "176UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:866: <b>switch_case</b>: Reached case "176UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:874: <b>negative_return_fn</b>: Function "IRQ_get_next(opp, &dst->raised)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:313:5: <b>cond_true</b>: Condition "q->next == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:313:5: <b>var_tested_neg</b>: Variable "q->next" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:318:5: <b>return_negative_variable</b>: Explicitly returning negative variable "q->next".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openpic.c:874: <b>var_assign</b>: Assigning: signed variable "n_IRQ" = "IRQ_get_next(openpic_t *, IRQ_queue_t *)".</span> qemu-kvm-1.2.0/hw/openpic.c:875: <b>negative_returns</b>: Using variable "n_IRQ" as an index to array "opp->src". <a name='def765'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def765'>[#def765]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:657: <b>negative_return_fn</b>: Function "ftell(f)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:657: <b>var_assign</b>: Assigning: signed variable "where" = "ftell(FILE *)".</span> qemu-kvm-1.2.0/hw/pc.c:660: <b>negative_returns</b>: "where" is passed to a parameter that cannot be negative. <a name='def766'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def766'>[#def766]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9615: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9627: <b>cond_true</b>: Condition "env->hflags & (1UL /* 1 << 0 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9630: <b>cond_true</b>: Condition "!!(env->flags & POWERPC_FLAG_CFAR)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9633: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_SPE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9633: <b>cond_true</b>: Condition "(env->msr >> 25) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9634: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9636: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9637: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_VRE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9637: <b>cond_true</b>: Condition "(env->msr >> 25) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9638: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9640: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9641: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_SE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9641: <b>cond_true</b>: Condition "(env->msr >> 10) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9642: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9644: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9645: <b>cond_true</b>: Condition "env->flags & POWERPC_FLAG_BE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9645: <b>cond_true</b>: Condition "(env->msr >> 9) & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9647: <b>cond_true</b>: Condition "!!env->singlestep_enabled", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9647: <b>cond_true</b>: Condition "!!env->singlestep_enabled", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9655: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9660: <b>cond_true</b>: Condition "ctx.exception == POWERPC_EXCP_NONE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9660: <b>cond_true</b>: Condition "gen_opc_ptr < gen_opc_end", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9661: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9661: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9662: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9663: <b>cond_true</b>: Condition "bp->pc == ctx.nip", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9665: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9667: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9669: <b>cond_true</b>: Condition "!!search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9669: <b>cond_true</b>: Condition "!!search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9671: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-ppc/translate.c:9675: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-ppc/translate.c:9676: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def767'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def767'>[#def767]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>cond_true</b>: Condition "so->s == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>var_tested_neg</b>: Variable "so->s" tests negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:828: <b>cond_false</b>: Condition "so->extra", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:831: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/slirp/slirp.c:833: <b>negative_returns</b>: "so->s" is passed to a parameter that cannot be negative. <a name='def768'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def768'>[#def768]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1215: <b>cond_false</b>: Condition "!!!(s->csr[0] & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1218: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1244: <b>var_tested_neg</b>: Assigning: "s->xmit_pos" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>negative_returns</b>: Using variable "s->xmit_pos" as an index to array "s->buffer". <a name='def769'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def769'>[#def769]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1215: <b>cond_false</b>: Condition "!!!(s->csr[0] & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1218: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1245: <b>goto</b>: Jumping to label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1275: <b>label</b>: Reached label "txdone"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_true</b>: Condition "(tmd.status & 0x200) >> 9", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1234: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1235: <b>cond_true</b>: Condition "(s->bcr[20] & 0xff) != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->csr[3] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1273: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_false</b>: Condition "!((tmd.status & 0x100) >> 8)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1252: <b>cond_true</b>: Condition "s->xmit_pos >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1254: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1254: <b>cond_true</b>: Condition "!!(s->csr[3] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1260: <b>cond_true</b>: Condition "!!(s->csr[15] & 4)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1261: <b>cond_false</b>: Condition "(s->bcr[20] & 0xff) == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1263: <b>cond_true</b>: Condition "add_crc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1266: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1268: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1272: <b>var_tested_neg</b>: Assigning: "s->xmit_pos" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1277: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1278: <b>cond_true</b>: Condition "!!!(s->csr[5] & 0x8000)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1281: <b>cond_true</b>: Condition "s->csr[74] <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1282: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1285: <b>cond_true</b>: Condition "count--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1286: <b>goto</b>: Jumping to label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1222: <b>label</b>: Reached label "txagain"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1223: <b>cond_true</b>: Condition "pcnet_tdte_poll(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1226: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1232: <b>cond_false</b>: Condition "(tmd.status & 0x200) >> 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1237: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "s->lnkst == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->csr[15] & 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_true</b>: Condition "!!!(s->csr[15] & 0x40)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1238: <b>cond_false</b>: Condition "!!!(s->bcr[2] & 0x4000)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1246: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1247: <b>cond_true</b>: Condition "!((tmd.status & 0x100) >> 8)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>cond_true</b>: Condition "!!(s->bcr[20] & 0x100)", taking true branch</span> qemu-kvm-1.2.0/hw/pcnet.c:1249: <b>negative_returns</b>: Using variable "s->xmit_pos" as an index to array "s->buffer". <a name='def770'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def770'>[#def770]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3370: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3395: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3400: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3400: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3401: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3402: <b>cond_true</b>: Condition "bp->pc == ctx.pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3404: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3406: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3408: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3410: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-alpha/translate.c:3414: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-alpha/translate.c:3415: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def771'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def771'>[#def771]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:326: <b>var_tested_neg</b>: Assigning: "rZ" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:328: <b>cond_false</b>: Condition "dc->format == OP_FMT_RI", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:331: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/target-lm32/translate.c:332: <b>negative_returns</b>: Using variable "rZ" as an index to array "cpu_R". <a name='def772'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def772'>[#def772]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1747: <b>cond_true</b>: Condition "!!(dc->tb_flags & (524288U /* 1 << 19 */))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1748: <b>cond_true</b>: Condition "dc->delayed_branch", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1757: <b>cond_false</b>: Condition "pc_start & 3", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1758: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1760: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1768: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1771: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1785: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1787: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-microblaze/translate.c:1791: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-microblaze/translate.c:1792: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def773'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def773'>[#def773]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "46"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7675: <b>switch_case</b>: Reached case "46"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7676: <b>negative_return_fn</b>: Function "low2highgid(arg1)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4604:5: <b>cond_true</b>: Condition "(int16_t)gid == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4605:9: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> qemu-kvm-1.2.0/linux-user/syscall.c:7676: <b>negative_returns</b>: "low2highgid(arg1)" is passed to a parameter that cannot be negative. <a name='def774'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def774'>[#def774]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7672: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7673: <b>negative_return_fn</b>: Function "low2highuid(arg1)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4596:5: <b>cond_true</b>: Condition "(int16_t)uid == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:4597:9: <b>return_negative_constant</b>: Explicitly returning negative value "-1".</span> qemu-kvm-1.2.0/linux-user/syscall.c:7673: <b>negative_returns</b>: "low2highuid(arg1)" is passed to a parameter that cannot be negative. <a name='def775'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def775'>[#def775]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5123: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5130: <b>cond_true</b>: Condition "!(tb->flags & (1ULL /* 0x100000000ULL >> 32 */))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5145: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5152: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5152: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5153: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5154: <b>cond_true</b>: Condition "bp->pc == dc.pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5156: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5158: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5160: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5162: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/translate.c:5167: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-s390x/translate.c:5168: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def776'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def776'>[#def776]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:602: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:607: <b>cond_false</b>: Condition "(so->so_tcpcb = tcp_newtcpcb(so)) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:610: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:616: <b>cond_true</b>: Condition "flags & 0x200", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:628: <b>cond_true</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking true branch</span> qemu-kvm-1.2.0/slirp/socket.c:634: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. <a name='def777'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def777'>[#def777]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_false</b>: Condition "path", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:684: <b>negative_return_fn</b>: Function "mkstemp(un.sun_path)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:684: <b>var_assign</b>: Assigning: signed variable "fd" = "mkstemp(char *)".</span> qemu-kvm-1.2.0/qemu-sockets.c:684: <b>negative_returns</b>: "fd" is passed to a parameter that cannot be negative. <a name='def778'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def778'>[#def778]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9708: <b>cond_true</b>: Condition "((tb->flags & (64UL /* 1 << 6 */)) >> 6) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9722: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9725: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9765: <b>cond_true</b>: Condition "dc->condexec_mask", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9782: <b>cond_true</b>: Condition "dc->pc >= 4294967280U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9782: <b>cond_false</b>: Condition "arm_feature(env, ARM_FEATURE_M)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9788: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9791: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9791: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9793: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9800: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9801: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9792: <b>cond_false</b>: Condition "bp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9801: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9803: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9805: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-arm/translate.c:9809: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-arm/translate.c:9810: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def779'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def779'>[#def779]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2989: <b>cond_true</b>: Condition "(env->sr & 8192) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2992: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:2995: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3002: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3002: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3004: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3008: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3009: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3003: <b>cond_false</b>: Condition "bp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3009: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3010: <b>cond_false</b>: Condition "dc->is_jmp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3011: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3013: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3015: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/translate.c:3019: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-m68k/translate.c:3020: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def780'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def780'>[#def780]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:404: <b>cond_false</b>: Condition "inso->so_state & 0x200", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:407: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:408: <b>cond_true</b>: Condition "(so = socreate(slirp)) == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/tcp_subr.c:410: <b>negative_return_fn</b>: Function "accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" returns a negative number.</span> qemu-kvm-1.2.0/slirp/tcp_subr.c:410: <b>negative_returns</b>: "accept(inso->s, __SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), &addrlen)" is passed to a parameter that cannot be negative. <a name='def781'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def781'>[#def781]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1928: <b>cond_true</b>: Condition "(env->sr & (1073741824U /* 1 << 30 */)) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1937: <b>var_tested_neg</b>: Assigning: "ii" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1940: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1943: <b>cond_true</b>: Condition "ctx.bstate == BS_NONE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1943: <b>cond_true</b>: Condition "gen_opc_ptr < gen_opc_end", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1944: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1944: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1945: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1946: <b>cond_true</b>: Condition "ctx.pc == bp->pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1951: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1953: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1955: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1957: <b>cond_false</b>: Condition "ii < i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sh4/translate.c:1961: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-sh4/translate.c:1962: <b>negative_returns</b>: Using variable "ii" as an index to array "gen_opc_pc". <a name='def782'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def782'>[#def782]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:526: <b>negative_return_fn</b>: Function "target_mprotect(start, len, prot)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:94:5: <b>cond_true</b>: Condition "(start & 8191U /* ~~((1 << 13) - 1) */) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:95:9: <b>return_negative_constant</b>: Explicitly returning negative value "-22".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:526: <b>var_assign</b>: Assigning: unsigned variable "ret" = "target_mprotect(abi_ulong, abi_ulong, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527: <b>cond_true</b>: Condition "ret != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:528: <b>var_assign</b>: Assigning: unsigned variable "start" = "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:529: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:584: <b>negative_returns</b>: "start" is passed to a parameter that cannot be negative.</span> qemu-kvm-1.2.0/exec.c:1076:5: <b>parm_loop_bound</b>: Using unsigned parameter "start" in a loop exit test. <a name='def783'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def783'>[#def783]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:253: <b>cond_true</b>: Condition "status < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:255: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:257: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:263: <b>negative_return_fn</b>: Function "v9fs_marshal(iovec, 1, 0UL, 0, "ddd", header.type, header.size, status)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_false</b>: Condition "copied < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:317:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:319:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_false</b>: Condition "copied < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:317:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:319:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:229:5: <b>cond_true</b>: Condition "fmt[i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:230:9: <b>switch</b>: Switch case value "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:231:14: <b>switch_case</b>: Reached case "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:234:13: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:313:9: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>cond_true</b>: Condition "copied < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:314:9: <b>var_tested_neg</b>: Variable "copied" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtio-9p-marshal.c:316:13: <b>return_negative_variable</b>: Explicitly returning negative variable "copied".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:263: <b>var_assign</b>: Assigning: signed variable "msg_size" = "v9fs_marshal(struct iovec *, int, size_t, int, char const *, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:265: <b>negative_returns</b>: "msg_size" is passed to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:159:5: <b>cond_true</b>: Condition "size", taking true branch</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:160:9: <b>neg_sink_parm_call</b>: Passing "size" to "write(int, void const *, size_t)", which cannot accept a negative number. <a name='def784'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def784'>[#def784]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12428: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12434: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12454: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12456: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12458: <b>cond_true</b>: Condition "ctx.bstate == BS_NONE", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12459: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12459: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12461: <b>cond_false</b>: Condition "bp->pc == ctx.pc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12469: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12460: <b>cond_false</b>: Condition "bp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12470: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12473: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12475: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-mips/translate.c:12479: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-mips/translate.c:12480: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def785'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def785'>[#def785]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1662: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. <a name='def786'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def786'>[#def786]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1228: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. <a name='def787'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def787'>[#def787]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2026: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. <a name='def788'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def788'>[#def788]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3189: <b>cond_true</b>: Condition "env->pregs[1] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3192: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3195: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3224: <b>cond_true</b>: Condition "!!(tb->flags & 7)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3225: <b>cond_true</b>: Condition "dc->delayed_branch", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3226: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3228: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3232: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3256: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3259: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3267: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3269: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3273: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3274: <b>cond_true</b>: Condition "dc->delayed_branch == 1", taking true branch</span> qemu-kvm-1.2.0/target-cris/translate.c:3275: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def789'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def789'>[#def789]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3189: <b>cond_true</b>: Condition "env->pregs[1] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3192: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3195: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3224: <b>cond_false</b>: Condition "!!(tb->flags & 7)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3225: <b>cond_false</b>: Condition "dc->delayed_branch", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3228: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3232: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3256: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3259: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3267: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3269: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3273: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3274: <b>cond_false</b>: Condition "dc->delayed_branch == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:3277: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/target-cris/translate.c:3277: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def790'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def790'>[#def790]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1968: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1971: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1985: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1985: <b>cond_true</b>: Condition "!!!(env->breakpoints.tqh_first == NULL)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>cond_true</b>: Condition "bp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1987: <b>cond_false</b>: Condition "bp->pc == dc->pc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1996: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1997: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1986: <b>cond_false</b>: Condition "bp", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1997: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:1999: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:2001: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-unicore32/translate.c:2006: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-unicore32/translate.c:2007: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def791'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def791'>[#def791]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:361: <b>cond_false</b>: Condition "!so", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:363: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:364: <b>negative_return_fn</b>: Function "qemu_socket(2, 2, 0)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/udp.c:364: <b>var_assign</b>: Assigning: signed variable "so->s" = "qemu_socket(int, int, int)".</span> qemu-kvm-1.2.0/slirp/udp.c:372: <b>negative_returns</b>: "so->s" is passed to a parameter that cannot be negative. <a name='def792'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def792'>[#def792]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_true</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking true branch</span> qemu-kvm-1.2.0/slirp/misc.c:139: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. <a name='def793'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def793'>[#def793]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>negative_return_fn</b>: Function "qemu_socket(2, 1, 0)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>var_tested_neg</b>: Variable "ret" is negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "*__errno_location() != 22", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_negative_variable</b>: Explicitly returning negative variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>var_assign</b>: Assigning: signed variable "s" = "qemu_socket(int, int, int)".</span> qemu-kvm-1.2.0/slirp/misc.c:165: <b>negative_returns</b>: "s" is passed to a parameter that cannot be negative. <a name='def794'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def794'>[#def794]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1685: <b>cond_true</b>: Condition "!!(dc->tb_flags & 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1687: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1693: <b>var_tested_neg</b>: Assigning: "k" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1697: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1705: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1707: <b>cond_false</b>: Condition "k < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-openrisc/translate.c:1712: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-openrisc/translate.c:1713: <b>negative_returns</b>: Using variable "k" as an index to array "gen_opc_pc". <a name='def795'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def795'>[#def795]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:462: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:496: <b>negative_returns</b>: A negative constant "-1" is passed as an argument to a parameter that cannot be negative.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_true</b>: Condition "!(flags & 0x10)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:431:9: <b>cond_false</b>: Condition "start == 4294967295U /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:434:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>neg_sink_parm_call</b>: Passing "fd" to "fstat(int, struct stat *)", which cannot accept a negative number. <a name='def796'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def796'>[#def796]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "parser", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>cond_true</b>: Condition "({...})", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:507: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "err", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "!obj", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:511: <b>cond_false</b>: Condition "qobject_type(obj) != QTYPE_QDICT", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:522: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>cond_false</b>: Condition "qdict", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>cond_true</b>: Condition "({...})", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:526: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:529: <b>cond_false</b>: Condition "qdict_haskey(qdict, "execute")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:531: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:532: <b>cond_false</b>: Condition "!qdict_haskey(qdict, "error")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:539: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:540: <b>negative_return_fn</b>: Function "send_response(s, &qdict->base)" returns a negative number.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "payload", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "s->channel", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>cond_true</b>: Condition "({...})", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:453:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:456:5: <b>cond_false</b>: Condition "!payload_qstr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:458:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:460:5: <b>cond_true</b>: Condition "s->delimit_response", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:465:9: <b>cond_true</b>: Condition "payload_qstr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:466:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:468:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:473:5: <b>cond_true</b>: Condition "response_qstr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:474:5: <b>cond_true</b>: Condition "status != G_IO_STATUS_NORMAL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:475:9: <b>return_negative_constant</b>: Explicitly returning negative value "-5".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:540: <b>var_assign</b>: Assigning: signed variable "ret" = "send_response(GAState *, QObject *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:541: <b>cond_true</b>: Condition "ret", taking true branch</span> qemu-kvm-1.2.0/qemu-ga.c:542: <b>negative_returns</b>: "ret" is passed to a parameter that cannot be negative. <a name='def797'/><b>Error: <span style='background: #C0FF00;'>NEGATIVE_RETURNS</span> (CWE-394):</b> <a href ='#def797'>[#def797]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1028: <b>cond_false</b>: Condition "pc_start & 3", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1030: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1032: <b>cond_true</b>: Condition "qemu_loglevel_mask(2 /* 1 << 1 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1038: <b>var_tested_neg</b>: Assigning: "lj" = a negative value.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1041: <b>cond_true</b>: Condition "max_insns == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1049: <b>cond_true</b>: Condition "search_pc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1051: <b>cond_false</b>: Condition "lj < j", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-lm32/translate.c:1056: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-lm32/translate.c:1057: <b>negative_returns</b>: Using variable "lj" as an index to array "gen_opc_pc". <a name='def798'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def798'>[#def798]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_false</b>: Condition "*p", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:856: <b>cond_true</b>: Condition "nr_sep >= 2", taking true branch</span> qemu-kvm-1.2.0/block/sheepdog.c:858: <b>returned_null</b>: Function "__coverity_strchr(char const *, int)" returns null (checked 51 out of 53 times). <span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:952: <b>example_assign</b>: Assigning: "e" = return value from "__coverity_strchr(p, 44)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:953: <b>example_checked</b>: "e" has its value checked in "e".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:281: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:282: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:85: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:86: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:214: <b>example_assign</b>: Assigning: "end" = return value from "__coverity_strchr(p, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:216: <b>example_checked</b>: "end" has its value checked in "end".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:871: <b>example_assign</b>: Assigning: "p" = return value from "__coverity_strchr(vdi, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:872: <b>example_checked</b>: "p" has its value checked in "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:858: <b>var_assigned</b>: Assigning: "p" = null return value from "__coverity_strchr(char const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:859: <b>dereference</b>: Incrementing a pointer which might be null: "p".</span> <a name='def799'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def799'>[#def799]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_true</b>: Condition "*p", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:848: <b>cond_true</b>: Condition "*p == ':'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:847: <b>cond_false</b>: Condition "*p", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:852: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:856: <b>cond_true</b>: Condition "nr_sep >= 2", taking true branch</span> qemu-kvm-1.2.0/block/sheepdog.c:862: <b>returned_null</b>: Function "__coverity_strchr(char const *, int)" returns null (checked 51 out of 53 times). <span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:952: <b>example_assign</b>: Assigning: "e" = return value from "__coverity_strchr(p, 44)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/arch_init.c:953: <b>example_checked</b>: "e" has its value checked in "e".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:281: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkdebug.c:282: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:85: <b>example_assign</b>: Assigning: "c" = return value from "__coverity_strchr(filename, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/blkverify.c:86: <b>example_checked</b>: "c" has its value checked in "c == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:214: <b>example_assign</b>: Assigning: "end" = return value from "__coverity_strchr(p, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/rbd.c:216: <b>example_checked</b>: "end" has its value checked in "end".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:871: <b>example_assign</b>: Assigning: "p" = return value from "__coverity_strchr(vdi, 58)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:872: <b>example_checked</b>: "p" has its value checked in "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:862: <b>var_assigned</b>: Assigning: "p" = null return value from "__coverity_strchr(char const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/sheepdog.c:863: <b>dereference</b>: Incrementing a pointer which might be null: "p".</span> <a name='def800'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def800'>[#def800]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:853: <b>cond_false</b>: Condition "!nc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:856: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/net.c:859: <b>returned_null</b>: Function "qemu_opts_find(QemuOptsList *, char const *)" returns null (checked 9 out of 10 times). <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:717:5: <b>cond_true</b>: Condition "opts", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:718:9: <b>cond_true</b>: Condition "!opts->id", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:719:13: <b>cond_false</b>: Condition "!id", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:721:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:722:13: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:728:5: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:717:5: <b>cond_false</b>: Condition "opts", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:728:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:729:5: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/device_tree.c:243: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/device_tree.c:244: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2482: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2483: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:354: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_boot.c:355: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/microblaze_boot.c:111: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/microblaze_boot.c:112: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc/e500.c:145: <b>example_assign</b>: Assigning: "machine_opts" = return value from "qemu_opts_find(qemu_find_opts("machine"), NULL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc/e500.c:146: <b>example_checked</b>: "machine_opts" has its value checked in "machine_opts".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:859: <b>dereference</b>: Dereferencing a pointer that might be null "qemu_opts_find(qemu_find_opts_err("netdev", errp), id)" when calling "qemu_opts_del(QemuOpts *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:822:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:823:9: <b>deref_parm</b>: Directly dereferencing parameter "opts".</span> <a name='def801'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def801'>[#def801]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:594: <b>cond_false</b>: Condition "!ad->res_fis", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:594: <b>cond_false</b>: Condition "!(pr->cmd & (16U /* 1 << 4 */))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:596: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:598: <b>cond_true</b>: Condition "!cmd_fis", taking true branch</span> qemu-kvm-1.2.0/hw/ide/ahci.c:601: <b>returned_null</b>: Function "dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)" returns null (checked 4 out of 5 times). <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:178:5: <b>cond_false</b>: Condition "!dma_has_iommu(dma)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:186:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:187:9: <b>null_return</b>: Calling "iommu_dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)" which might return null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:397:5: <b>cond_false</b>: Condition "dma->map", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:399:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:403:5: <b>cond_true</b>: Condition "err", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:404:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:187:9: <b>return_null_fn</b>: Returning the return value of "iommu_dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)", which might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:158: <b>example_assign</b>: Assigning: "mem" = return value from "dma_memory_map(dbs->sg->dma, cur_addr, &cur_len, dbs->dir)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:159: <b>example_checked</b>: "mem" has its value checked in "mem".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:661: <b>example_checked</b>: "dma_memory_map(ad->hba->dma, prdt_addr, &prdt_len, DMA_DIRECTION_TO_DEVICE)" has its value checked in "prdt = dma_memory_map(ad->hba->dma, prdt_addr, &prdt_len, DMA_DIRECTION_TO_DEVICE)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:840: <b>example_assign</b>: Assigning: "cmd_fis" = return value from "dma_memory_map(s->dma, tbl_addr, &cmd_len, DMA_DIRECTION_FROM_DEVICE)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:843: <b>example_checked</b>: "cmd_fis" has its value checked in "cmd_fis".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/libhw.c:37: <b>example_assign</b>: Assigning: "mem" = return value from "dma_memory_map(sgl->dma, (sgl->sg + i).base, &len, dir)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/libhw.c:38: <b>example_checked</b>: "mem" has its value checked in "mem".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:601: <b>var_assigned</b>: Assigning: "cmd_fis" = null return value from "dma_memory_map(DMAContext *, dma_addr_t, dma_addr_t *, DMADirection)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:609: <b>cond_true</b>: Condition "ad->hba->control_regs.irqstatus", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ide/ahci.c:613: <b>dereference</b>: Dereferencing a null pointer "cmd_fis".</span> <a name='def802'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def802'>[#def802]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "273"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8547: <b>switch_case</b>: Reached case "273"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8552: <b>cond_false</b>: Condition "arg5 != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8558: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8558: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_send(mqd_t, char const *, size_t, unsigned int)".</span> <a name='def803'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def803'>[#def803]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "273"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8547: <b>switch_case</b>: Reached case "273"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8551: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8552: <b>cond_true</b>: Condition "arg5 != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8554: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_timedsend(mqd_t, char const *, size_t, unsigned int, struct timespec const *)".</span> <a name='def804'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def804'>[#def804]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "274"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8563: <b>switch_case</b>: Reached case "274"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8569: <b>cond_false</b>: Condition "arg5 != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8575: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8575: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_receive(mqd_t, char *, size_t, unsigned int *)".</span> <a name='def805'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def805'>[#def805]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "274"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8563: <b>switch_case</b>: Reached case "274"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8568: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8569: <b>cond_true</b>: Condition "arg5 != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8571: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_timedreceive(mqd_t, char * restrict, size_t, unsigned int * restrict, struct timespec const * restrict)".</span> <a name='def806'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def806'>[#def806]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "271"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8529: <b>switch_case</b>: Reached case "271"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8533: <b>returned_null</b>: Function "lock_user_string(abi_ulong)" returns null (checked 8 out of 9 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>null_return</b>: Calling "lock_user(int, abi_ulong, long, int)" which might return null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_null_fn</b>: Returning the return value of "lock_user(int, abi_ulong, long, int)", which might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:627: <b>example_checked</b>: "lock_user_string(addr)" has its value checked in "(s = lock_user_string(addr)) != NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:236: <b>example_checked</b>: "lock_user_string(arg1)" has its value checked in "s = lock_user_string(arg1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:263: <b>example_assign</b>: Assigning: "p" = return value from "lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:265: <b>example_checked</b>: "p" has its value checked in "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:281: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8533: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user_string(abi_ulong)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8534: <b>cond_true</b>: Condition "arg4 != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8536: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_open(char const *, int, ...)".</span> <a name='def807'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def807'>[#def807]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "272"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8541: <b>switch_case</b>: Reached case "272"</span> qemu-kvm-1.2.0/linux-user/syscall.c:8542: <b>returned_null</b>: Function "lock_user_string(abi_ulong)" returns null (checked 8 out of 9 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>null_return</b>: Calling "lock_user(int, abi_ulong, long, int)" which might return null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_null_fn</b>: Returning the return value of "lock_user(int, abi_ulong, long, int)", which might be null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:627: <b>example_checked</b>: "lock_user_string(addr)" has its value checked in "(s = lock_user_string(addr)) != NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/strace.c:236: <b>example_checked</b>: "lock_user_string(arg1)" has its value checked in "s = lock_user_string(arg1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:263: <b>example_assign</b>: Assigning: "p" = return value from "lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:265: <b>example_checked</b>: "p" has its value checked in "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:281: <b>example_checked</b>: "lock_user_string(({...}))" has its value checked in "p = lock_user_string(({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8542: <b>var_assigned</b>: Assigning: "p" = null return value from "lock_user_string(abi_ulong)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8543: <b>dereference</b>: Dereferencing a pointer that might be null "p" when calling "mq_unlink(char const *)".</span> <a name='def808'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def808'>[#def808]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737481U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3473: <b>switch_case</b>: Reached case "3241737481U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3475: <b>alias</b>: Assigning: "gspec" = "argptr". Both pointers are now null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3481: <b>cond_true</b>: Condition "i < host_dm->target_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3486: <b>dereference</b>: Dereferencing a pointer that might be null "gspec" when calling "thunk_convert(void *, void const *, argtype const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:133:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:134:10: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:135:9: <b>deref_parm</b>: Directly dereferencing parameter "src".</span> <a name='def809'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def809'>[#def809]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737486U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3469: <b>switch_case</b>: Reached case "3241737486U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3471: <b>dereference</b>: Dereferencing a null pointer "argptr".</span> <a name='def810'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def810'>[#def810]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737477U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3464: <b>switch_case</b>: Reached case "3241737477U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3467: <b>dereference</b>: Dereferencing a pointer that might be null "argptr" when calling "memcpy(void * restrict, void const * restrict, size_t)".</span> <a name='def811'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def811'>[#def811]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3449: <b>var_assigned</b>: Assigning: "argptr" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737486U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3469: <b>switch_case</b>: Reached case "3241737486U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3470: <b>dereference</b>: Dereferencing a pointer that might be null "argptr" when calling "memcpy(void * restrict, void const * restrict, size_t)".</span> <a name='def812'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def812'>[#def812]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1934: <b>cond_true</b>: Condition "*s == 'p'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_true</b>: Condition "*s == 'm'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1942: <b>cond_false</b>: Condition "*s == 'M'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1942: <b>cond_false</b>: Condition "*s == 'z'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1953: <b>cond_true</b>: Condition "opcodep->match != 3583U /* 255 + 13 * 256 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1958: <b>cond_true</b>: Condition "opcodep->name[0] == 'j'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1960: <b>cond_true</b>: Condition "__coverity_strncmp(opcodep->name, "jsr", 3UL /* sizeof ("jsr") - 1 */) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1962: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1965: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'T'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1976: <b>switch_case</b>: Reached case "'T'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1978: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'N'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2053: <b>switch_case</b>: Reached case "'N'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "(insn & 15) == 15", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "prefix_opcodep == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2069: <b>cond_false</b>: Condition "opcodep->imm_oprnd_size == SIZE_FIX_32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2071: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2071: <b>cond_true</b>: Condition "opcodep->imm_oprnd_size == SIZE_SPEC_REG", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2079: <b>cond_true</b>: Condition "sregp == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2081: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2086: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2088: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2097: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2099: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2119: <b>switch_default</b>: Reached default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2125: <b>cond_true</b>: Condition "*cs == 'z'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2125: <b>cond_true</b>: Condition "insn & 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2128: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2156: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2157: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2410: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2411: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'N'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2053: <b>switch_case</b>: Reached case "'N'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2059: <b>cond_false</b>: Condition "(insn & 15) == 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2159: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2162: <b>cond_true</b>: Condition "info->insn_type != dis_nonbranch", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2171: <b>cond_false</b>: Condition "opcodep->imm_oprnd_size == SIZE_FIX_32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2173: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2173: <b>cond_true</b>: Condition "opcodep->imm_oprnd_size == SIZE_SPEC_REG", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2180: <b>cond_true</b>: Condition "sregp == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2181: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2183: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2184: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2186: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2193: <b>cond_false</b>: Condition "prefix_opcodep", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2400: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2406: <b>cond_true</b>: Condition "insn & 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2411: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2423: <b>switch_case</b>: Reached case "'b'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2427: <b>cond_true</b>: Condition "where > 32767", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2430: <b>cond_true</b>: Condition "disdata->distype == cris_dis_v32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2432: <b>cond_true</b>: Condition "insn == 60927U /* (13 + 14 * 16) * 256 + 255 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2433: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2435: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2446: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'o'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2456: <b>switch_case</b>: Reached case "'o'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2461: <b>cond_true</b>: Condition "insn & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2464: <b>cond_true</b>: Condition "opcodep->match == 57344U /* (0 + 14 * 16) * 256 + 0 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2465: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2467: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2469: <b>cond_true</b>: Condition "disdata->distype == cris_dis_v32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2521: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2522: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'P'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2500: <b>switch_case</b>: Reached case "'P'"</span> qemu-kvm-1.2.0/cris-dis.c:2503: <b>returned_null</b>: Function "spec_reg_info(unsigned int, enum cris_disass_family)" returns null (checked 5 out of 6 times). <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_true</b>: Condition "cris_spec_regs[i].name != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1337:7: <b>cond_true</b>: Condition "cris_spec_regs[i].number == sreg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1339:4: <b>cond_true</b>: Condition "distype == cris_dis_v32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1340:6: <b>switch</b>: Switch case value "cris_ver_warning"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1342:13: <b>switch_case</b>: Reached case "cris_ver_warning"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1349:3: <b>cond_false</b>: Condition "cris_spec_regs[i].warning == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1350:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1353:8: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1355:6: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_true</b>: Condition "cris_spec_regs[i].name != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1337:7: <b>cond_true</b>: Condition "cris_spec_regs[i].number == sreg", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1339:4: <b>cond_true</b>: Condition "distype == cris_dis_v32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1340:6: <b>switch</b>: Switch case value "cris_ver_warning"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1342:13: <b>switch_case</b>: Reached case "cris_ver_warning"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1349:3: <b>cond_false</b>: Condition "cris_spec_regs[i].warning == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1350:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1353:8: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1355:6: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1335:3: <b>cond_false</b>: Condition "cris_spec_regs[i].name != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1357:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1359:3: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1850: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, distype)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1854: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1671: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info(spec_reg, disdata->distype)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1675: <b>example_checked</b>: "sregp" has its value checked in "sregp".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1700: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1714: <b>example_checked</b>: "sregp" has its value checked in "sregp != NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2074: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2079: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2176: <b>example_assign</b>: Assigning: "sregp" = return value from "spec_reg_info((insn >> 12) & 0xfU, disdata->distype)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2180: <b>example_checked</b>: "sregp" has its value checked in "sregp == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2503: <b>var_assigned</b>: Assigning: "sregp" = null return value from "spec_reg_info(unsigned int, enum cris_disass_family)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2505: <b>dereference</b>: Dereferencing a null pointer "sregp".</span> <a name='def813'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def813'>[#def813]</a> qemu-kvm-1.2.0/block/vpc.c:665: <b>returned_null</b>: Function "get_option_parameter(QEMUOptionParameter *, char const *)" returns null (checked 10 out of 11 times). <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list->name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:163:9: <b>cond_false</b>: Condition "!__coverity_strcmp(list->name, name)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:165:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:167:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_true</b>: Condition "list", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:162:5: <b>cond_false</b>: Condition "list->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:167:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:169:5: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:667: <b>example_assign</b>: Assigning: "disk_type_param" = return value from "get_option_parameter(options, "subformat")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:668: <b>example_checked</b>: "disk_type_param" has its value checked in "disk_type_param".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3969: <b>example_assign</b>: Assigning: "backing_file" = return value from "get_option_parameter(param, "backing_file")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:3970: <b>example_checked</b>: "backing_file" has its value checked in "backing_file".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-img.c:827: <b>example_assign</b>: Assigning: "out_baseimg_param" = return value from "get_option_parameter(param, "backing_file")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-img.c:828: <b>example_checked</b>: "out_baseimg_param" has its value checked in "out_baseimg_param".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:393: <b>example_checked</b>: "get_option_parameter(dest, list->name)" has its value checked in "get_option_parameter(dest, list->name) == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:267: <b>example_assign</b>: Assigning: "list" = return value from "get_option_parameter(list, name)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-option.c:268: <b>example_checked</b>: "list" has its value checked in "list == NULL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vpc.c:665: <b>dereference</b>: Dereferencing a null pointer "get_option_parameter(options, "size")".</span> <a name='def814'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def814'>[#def814]</a> qemu-kvm-1.2.0/target-sparc/cpu.c:647: <b>returned_null</b>: Function "strtok(char * restrict, char const * restrict)" returns null (checked 9 out of 10 times). <span style='color: #808080;'>qemu-kvm-1.2.0/hw/acpi.c:118: <b>example_assign</b>: Assigning: "f" = return value from "strtok(NULL, ":")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/acpi.c:118: <b>example_checked</b>: "f" has its value checked in "f".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-timer.c:190: <b>example_assign</b>: Assigning: "name" = return value from "strtok(arg, ",")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-timer.c:191: <b>example_checked</b>: "name" has its value checked in "name".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/cpu.c:1020: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/cpu.c:911: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:663: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:664: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:731: <b>example_assign</b>: Assigning: "featurestr" = return value from "strtok(NULL, ",")".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:664: <b>example_checked</b>: "featurestr" has its value checked in "featurestr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:647: <b>var_assigned</b>: Assigning: "name" = null return value from "strtok(char * restrict, char const * restrict)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:653: <b>cond_true</b>: Condition "i < 22UL /* sizeof (sparc_defs) / sizeof (sparc_defs[0]) */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-sparc/cpu.c:654: <b>dereference</b>: Dereferencing a pointer that might be null "name" when calling "strcasecmp(char const *, char const *)".</span> <a name='def815'/><b>Error: <span style='background: #C0FF00;'>NULL_RETURNS</span> (CWE-476):</b> <a href ='#def815'>[#def815]</a> qemu-kvm-1.2.0/linux-user/flatload.c:102: <b>returned_null</b>: Function "lock_user(int, abi_ulong, long, int)" returns null (checked 253 out of 260 times). <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_true</b>: Condition "!access_ok(type, guest_addr, len)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>return_null</b>: Explicitly returning null.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:52: <b>example_checked</b>: "lock_user(0, __gaddr, 4L, 1)" has its value checked in "__hptr = lock_user(0, __gaddr, 4L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/fpa11_cpdt.c:198: <b>example_checked</b>: "lock_user(1, __gaddr, 4L, 0)" has its value checked in "__hptr = lock_user(1, __gaddr, 4L, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2416: <b>example_checked</b>: "lock_user(0, target_addr, 64L, 1)" has its value checked in "target_sd = lock_user(0, target_addr, 64L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2717: <b>example_checked</b>: "lock_user(0, target_addr, 88L, 1)" has its value checked in "target_md = lock_user(0, target_addr, 88L, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1784: <b>example_assign</b>: Assigning: "target_vec" = return value from "lock_user(0, target_addr, count * 8UL, 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:1785: <b>example_checked</b>: "target_vec" has its value checked in "target_vec".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:102: <b>var_assigned</b>: Assigning: "buf" = null return value from "lock_user(int, abi_ulong, long, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/flatload.c:103: <b>dereference</b>: Dereferencing a pointer that might be null "buf" when calling "pread(int, void *, size_t, __off64_t)".</span> <a name='def816'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def816'>[#def816]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:1322: <b>overrun-buffer-arg</b>: Overrunning struct type evt_encrypt_change of 4 bytes by passing it to a function which accesses it at byte offset 4 using argument "5".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:461:5: <b>cond_false</b>: Condition "!packet", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:462:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci.c:464:5: <b>cond_true</b>: Condition "len", taking true branch</span> qemu-kvm-1.2.0/hw/bt-hci.c:465:9: <b>access_dbuff_in_call</b>: Calling "memcpy(void * restrict, void const * restrict, size_t)" indexes array "params" with index "len". <a name='def817'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def817'>[#def817]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_false</b>: Condition "offset < 2048", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_at_least</b>: Checking "offset < 2048UL" implies that the value of "offset" is at least 2048 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>cond_true</b>: Condition "offset < 3072", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:288: <b>cond_between</b>: Checking "offset < 3072UL" implies that the value of "offset" is between 2048 and 3071 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:290: <b>cond_false</b>: Condition "s->num_cpu == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:293: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:294: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:294: <b>assignment</b>: Assigning: "irq" = "offset - 2048UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:295: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:297: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:298: <b>cond_true</b>: Condition "irq >= 29", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:298: <b>cond_false</b>: Condition "irq <= 31", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:300: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:301: <b>overrun-local</b>: Overrunning array "s->irq_target" of 1020 4-byte elements at element index 1055 (byte offset 4220) using index "irq" (which evaluates to 1055). <a name='def818'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def818'>[#def818]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:254: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:270: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_true</b>: Condition "offset < 2048", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:282: <b>cond_between</b>: Checking "offset < 2048UL" implies that the value of "offset" is between 1024 and 2047 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:284: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:284: <b>assignment</b>: Assigning: "irq" = "offset - 1024UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:285: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:286: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:287: <b>cond_false</b>: Condition "irq < 32", taking false branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:287: <b>overrun-local</b>: Overrunning array "s->priority2" of 988 4-byte elements at element index 1023 (byte offset 4092) using index "irq - 32" (which evaluates to 1023). <a name='def819'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def819'>[#def819]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:227: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_true</b>: Condition "offset < 512", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:239: <b>cond_between</b>: Checking "offset < 512UL" implies that the value of "offset" is between 256 and 511 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:241: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:241: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:242: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL". The value of "irq" is now between 0 and 1016 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:242: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:244: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:245: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:245: <b>assignment</b>: Assigning: "irq" += "(s->revision == 4294967295U) ? 32 : 0". The value of "irq" is now between 32 and 1048 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:246: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:247: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:249: <b>assignment</b>: Assigning: "i" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:249: <b>cond_true</b>: Condition "i < 8", taking true branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:250: <b>overrun-local</b>: Overrunning array "s->irq_state" of 1020 8-byte elements at element index 1048 (byte offset 8384) using index "irq + i" (which evaluates to 1048). <a name='def820'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def820'>[#def820]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_false</b>: Condition "offset < 384", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_at_least</b>: Checking "offset < 384UL" implies that the value of "offset" is at least 384 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>cond_false</b>: Condition "offset < 512", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:392: <b>cond_at_least</b>: Checking "offset < 512UL" implies that the value of "offset" is at least 512 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>cond_false</b>: Condition "offset < 640", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:409: <b>cond_at_least</b>: Checking "offset < 640UL" implies that the value of "offset" is at least 640 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>cond_false</b>: Condition "offset < 768", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:422: <b>cond_at_least</b>: Checking "offset < 768UL" implies that the value of "offset" is at least 768 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>cond_false</b>: Condition "offset < 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:435: <b>cond_at_least</b>: Checking "offset < 1024UL" implies that the value of "offset" is at least 1024 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>cond_true</b>: Condition "offset < 2048", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:438: <b>cond_between</b>: Checking "offset < 2048UL" implies that the value of "offset" is between 1024 and 2047 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:440: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:440: <b>assignment</b>: Assigning: "irq" = "offset - 1024UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1055 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:441: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:442: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:443: <b>cond_false</b>: Condition "irq < 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:445: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:446: <b>overrun-local</b>: Overrunning array "s->priority2" of 988 4-byte elements at element index 1023 (byte offset 4092) using index "irq - 32" (which evaluates to 1023). <a name='def821'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def821'>[#def821]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1048 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:370: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:371: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:372: <b>cond_false</b>: Condition "irq < 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:373: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>assignment</b>: Assigning: "i" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:375: <b>cond_true</b>: Condition "value & (1 << i)", taking true branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:379: <b>overrun-local</b>: Overrunning array "s->irq_state" of 1020 8-byte elements at element index 1048 (byte offset 8384) using index "irq + i" (which evaluates to 1048). <a name='def822'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def822'>[#def822]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_false</b>: Condition "offset < 256", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:356: <b>cond_at_least</b>: Checking "offset < 256UL" implies that the value of "offset" is at least 256 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_true</b>: Condition "offset < 384", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:367: <b>cond_between</b>: Checking "offset < 384UL" implies that the value of "offset" is between 256 and 383 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>cond_true</b>: Condition "s->revision == 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:369: <b>assignment</b>: Assigning: "irq" = "(offset - 256UL) * 8UL + ((s->revision == 4294967295U) ? 32 : 0)". The value of "irq" is now between 32 and 1048 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:370: <b>cond_false</b>: Condition "irq >= s->num_irq", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:371: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:372: <b>cond_false</b>: Condition "irq < 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:373: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:374: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/arm_gic.c:375: <b>cond_true</b>: Condition "value & (1 << i)", taking true branch</span> qemu-kvm-1.2.0/hw/arm_gic.c:376: <b>overrun-local</b>: Overrunning array "s->irq_target" of 1020 4-byte elements at element index 1048 (byte offset 4192) using index "irq" (which evaluates to 1048). <a name='def823'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def823'>[#def823]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_true</b>: Condition "r > 15", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:195: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:197: <b>cond_false</b>: Condition "r == 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:199: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:199: <b>cond_false</b>: Condition "r == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:202: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/target-cris/translate.c:202: <b>overrun-local</b>: Overrunning array "cpu_PR" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). <a name='def824'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def824'>[#def824]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:274: <b>cond_false</b>: Condition "c == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:275: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:276: <b>cond_true</b>: Condition "c == 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:279: <b>cond_true</b>: Condition "mon->outbuf_index >= 1023UL /* sizeof (mon->outbuf) - 1 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:279: <b>cond_at_least</b>: Checking "mon->outbuf_index >= 1023UL" implies that the value of "mon->outbuf_index" is at least 1023 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:282: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:272: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:274: <b>cond_false</b>: Condition "c == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:275: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:276: <b>cond_true</b>: Condition "c == 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/monitor.c:277: <b>incr</b>: Incrementing "mon->outbuf_index". The value of "mon->outbuf_index" is now at least 1024.</span> qemu-kvm-1.2.0/monitor.c:278: <b>overrun-local</b>: Overrunning array "mon->outbuf" of 1024 bytes at byte offset 1024 using index "mon->outbuf_index++" (which evaluates to 1024). <a name='def825'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def825'>[#def825]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:56: <b>cond_false</b>: Condition "addr == 1008", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:58: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:60: <b>switch</b>: Switch case value "255"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:69: <b>switch_case</b>: Reached case "255"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:69: <b>equality_cond</b>: Jumping to case "255".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:71: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/vt82c686.c:92: <b>switch_end</b>: Reached end of switch</span> qemu-kvm-1.2.0/hw/vt82c686.c:93: <b>overrun-local</b>: Overrunning array "superio_conf->config" of 255 bytes at byte offset 255 using index "superio_conf->index" (which evaluates to 255). <a name='def826'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def826'>[#def826]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:242: <b>cond_true</b>: Condition "bytes > s->prefetch.count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:251: <b>cond_false</b>: Condition "fptr < 64 - bytes", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:254: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:255: <b>cond_true</b>: Condition "fptr < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:255: <b>cond_at_most</b>: Checking "fptr < 64" implies that the value of "fptr" may be up to 63 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:256: <b>cond_true</b>: Condition "is16bit", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/omap_gpmc.c:258: <b>incr</b>: Incrementing "fptr". The value of "fptr" may now be up to 64.</span> qemu-kvm-1.2.0/hw/omap_gpmc.c:259: <b>overrun-local</b>: Overrunning array "s->prefetch.fifo" of 64 bytes at byte offset 64 using index "fptr++" (which evaluates to 64). <a name='def827'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def827'>[#def827]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:674: <b>cond_true</b>: Condition "s->idx_in >= 4096UL /* sizeof (s->data_in) */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:674: <b>cond_at_least</b>: Checking "s->idx_in >= 4096UL" implies that the value of "s->idx_in" is at least 4096 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/wm8750.c:677: <b>alias</b>: Assigning: "data" = "&s->data_in[s->idx_in]". "data" may now point to element 1024 (and beyond) of "s->data_in" (which consists of 1024 4-byte elements).</span> qemu-kvm-1.2.0/hw/wm8750.c:680: <b>overrun-local</b>: Overrunning array of 1024 4-byte elements at element index 1024 (byte offset 4096) by dereferencing pointer "data". <a name='def828'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def828'>[#def828]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1157: <b>cond_false</b>: Condition "ptr & 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1159: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1167: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1169: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1172: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1176: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1178: <b>cond_true</b>: Condition "env->cr[4] & (512U /* 1 << 9 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1182: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1183: <b>assignment</b>: Assigning: "nb_xmm_regs" = "16".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1184: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1186: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1189: <b>cond_true</b>: Condition "!(env->efer & (16384UL /* 1 << 14 */))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1196: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1192: <b>cond_at_most</b>: Checking "i < nb_xmm_regs" implies that the value of "i" may be up to 15 on the true branch.</span> qemu-kvm-1.2.0/target-i386/fpu_helper.c:1193: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). <a name='def829'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def829'>[#def829]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1095: <b>cond_false</b>: Condition "ptr & 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1097: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1101: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1103: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1121: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1125: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1127: <b>cond_true</b>: Condition "env->cr[4] & (512U /* 1 << 9 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1131: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1132: <b>assignment</b>: Assigning: "nb_xmm_regs" = "16".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1133: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1135: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1138: <b>cond_true</b>: Condition "!(env->efer & (16384UL /* 1 << 14 */))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1145: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_true</b>: Condition "i < nb_xmm_regs", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/fpu_helper.c:1141: <b>cond_at_most</b>: Checking "i < nb_xmm_regs" implies that the value of "i" may be up to 15 on the true branch.</span> qemu-kvm-1.2.0/target-i386/fpu_helper.c:1142: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). <a name='def830'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def830'>[#def830]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:274: <b>switch</b>: Switch case value "1256UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:303: <b>switch_case</b>: Reached case "1256UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:303: <b>equality_cond</b>: Jumping to case "1256UL".</span> qemu-kvm-1.2.0/hw/musicpal.c:304: <b>overrun-local</b>: Overrunning array "s->tx_queue" of 2 4-byte elements at element index 2 (byte offset 8) using index "(offset - 1248UL) / 4UL" (which evaluates to 2). <a name='def831'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def831'>[#def831]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:316: <b>switch</b>: Switch case value "1256UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:357: <b>switch_case</b>: Reached case "1256UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/musicpal.c:357: <b>equality_cond</b>: Jumping to case "1256UL".</span> qemu-kvm-1.2.0/hw/musicpal.c:358: <b>overrun-local</b>: Overrunning array "s->tx_queue" of 2 4-byte elements at element index 2 (byte offset 8) using index "(offset - 1248UL) / 4UL" (which evaluates to 2). <a name='def832'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def832'>[#def832]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:206: <b>cond_false</b>: Condition "shift > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:208: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:206: <b>cond_at_most</b>: Checking "shift > 16" implies that the value of "shift" may be up to 16 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:209: <b>assignment</b>: Assigning: "i" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:209: <b>cond_true</b>: Condition "i < 16 - shift", taking true branch</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:210: <b>overrun-local</b>: Overrunning array "d->_b" of 16 bytes at byte offset 16 using index "i + shift" (which evaluates to 16). <a name='def833'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def833'>[#def833]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:298: <b>assignment</b>: Assigning: "quality" = "vs->tight.quality".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:300: <b>cond_false</b>: Condition "!vs->vd->lossy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:302: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "ds_get_bytes_per_pixel(vs->ds) == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "vs->clientds.pf.bytes_per_pixel == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "w < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:304: <b>cond_false</b>: Condition "h < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:308: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:310: <b>cond_false</b>: Condition "vs->tight.quality != 255 /* (uint8_t)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:314: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:315: <b>cond_false</b>: Condition "w * h < tight_conf[compression].gradient_min_rect_size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:320: <b>cond_true</b>: Condition "vs->clientds.pf.bytes_per_pixel == 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:321: <b>cond_false</b>: Condition "vs->tight.pixel24", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:327: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:330: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:332: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/vnc-enc-tight.c:333: <b>cond_true</b>: Condition "quality != -1", taking true branch</span> qemu-kvm-1.2.0/ui/vnc-enc-tight.c:334: <b>overrun-local</b>: Overrunning array "tight_conf" of 10 56-byte elements at element index 255 (byte offset 14280) using index "quality" (which evaluates to 255). <a name='def834'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def834'>[#def834]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:526: <b>cond_false</b>: Condition "dtype == 536870912", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>cond_true</b>: Condition "dtype == (537919488U /* 0x20000000 | 0x100000 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_true</b>: Condition "tp->size == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_const</b>: Checking "tp->size == 0" implies that the value of "tp->size" is 0 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:551: <b>cond_true</b>: Condition "txd_lower & 67108864", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:552: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:555: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "vlan_enabled(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "is_vlan_txd(txd_lower)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->tse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:572: <b>cond_true</b>: Condition "tp->size + bytes > msh", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_true</b>: Condition "65536UL /* sizeof (tp->data) */ - tp->size < bytes", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_at_least</b>: Checking "65536UL - tp->size < bytes" implies that the value of "bytes" is at least 65537 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>assignment</b>: Assigning: "bytes" = "(65536UL - tp->size < bytes) ? 65536UL - tp->size : bytes". The value of "bytes" is now 65536.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>assignment</b>: Assigning: "sz" = "tp->size + bytes". The value of "sz" is now 65536.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_false</b>: Condition "(sz = tp->size + bytes) >= hdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:578: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_at_least</b>: Checking "(sz = tp->size + bytes) >= hdr" implies that the value of "hdr" is at least 65537 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:581: <b>cond_true</b>: Condition "sz == msh", taking true branch</span> qemu-kvm-1.2.0/hw/e1000.c:583: <b>overrun-buffer-arg</b>: Overrunning array "tp->data" of 65536 bytes by passing it to a function which accesses it at byte offset 65536 using argument "hdr" (which evaluates to 65537). <a name='def835'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def835'>[#def835]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:526: <b>cond_false</b>: Condition "dtype == 536870912", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:546: <b>cond_true</b>: Condition "dtype == (537919488U /* 0x20000000 | 0x100000 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_true</b>: Condition "tp->size == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:548: <b>cond_const</b>: Checking "tp->size == 0" implies that the value of "tp->size" is 0 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:551: <b>cond_true</b>: Condition "txd_lower & 67108864", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:552: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:555: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "vlan_enabled(s)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "is_vlan_txd(txd_lower)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:557: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->tse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:567: <b>cond_true</b>: Condition "tp->cptse", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:572: <b>cond_true</b>: Condition "tp->size + bytes > msh", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:575: <b>cond_true</b>: Condition "65536UL /* sizeof (tp->data) */ - tp->size < bytes", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_true</b>: Condition "(sz = tp->size + bytes) >= hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_true</b>: Condition "tp->size < hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/e1000.c:577: <b>cond_between</b>: Checking "tp->size < hdr" implies that the value of "hdr" is between 1 and 65536 (inclusive) on the true branch.</span> qemu-kvm-1.2.0/hw/e1000.c:578: <b>overrun-buffer-arg</b>: Overrunning array "tp->header" of 256 bytes by passing it to a function which accesses it at byte offset 65535 using argument "hdr" (which evaluates to 65536). <a name='def836'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def836'>[#def836]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:756: <b>assignment</b>: Assigning: "size" = "0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:758: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:762: <b>cond_false</b>: Condition "tcb_bytes > 2600", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:765: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:766: <b>cond_false</b>: Condition "tcb_bytes > 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:766: <b>cond_true</b>: Condition "tbd_array != 4294967295U", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:769: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:770: <b>cond_true</b>: Condition "tcb_bytes <= 2600UL /* sizeof (buf) */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:771: <b>cond_false</b>: Condition "size < tcb_bytes", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:784: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:785: <b>cond_false</b>: Condition "tbd_array == 4294967295U", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:787: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:790: <b>cond_true</b>: Condition "s->has_extended_tcb_support", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:790: <b>cond_true</b>: Condition "!(s->configuration[6] & (16 /* 1 << 4 */))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:792: <b>cond_true</b>: Condition "tbd_count < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:800: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>cond_false</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>cond_at_least</b>: Checking "tx_buffer_size < 2600UL - size" implies that the value of "tx_buffer_size" is at least 2600 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:803: <b>assignment</b>: Assigning: "tx_buffer_size" = "(tx_buffer_size < 2600UL - size) ? tx_buffer_size : (2600UL - size)". The value of "tx_buffer_size" is now 2600.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:806: <b>assignment</b>: Assigning: "size" += "tx_buffer_size". The value of "size" is now 2600.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:807: <b>cond_true</b>: Condition "tx_buffer_el & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:808: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:810: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>cond_true</b>: Condition "tbd_count < s->tx.tbd_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:818: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_false</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_at_least</b>: Checking "tx_buffer_size < 2600UL - size" implies that the value of "tx_buffer_size" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>assignment</b>: Assigning: "tx_buffer_size" = "(tx_buffer_size < 2600UL - size) ? tx_buffer_size : (2600UL - size)". The value of "tx_buffer_size" is now 0.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:824: <b>assignment</b>: Assigning: "size" += "tx_buffer_size". The value of "size" is now 2600.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:825: <b>cond_false</b>: Condition "tx_buffer_el & 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:827: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:828: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:813: <b>cond_true</b>: Condition "tbd_count < s->tx.tbd_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:818: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:821: <b>cond_true</b>: Condition "tx_buffer_size < 2600UL /* sizeof (buf) */ - size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/eepro100.c:822: <b>overrun-local</b>: Overrunning array of 2600 bytes at byte offset 2600 by dereferencing pointer "&buf[size]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pci.h:605:5: <b>deref_parm_in_call</b>: Function "pci_dma_rw(PCIDevice *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pci.h:598:5: <b>deref_parm_in_call</b>: Function "dma_memory_rw(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:150:5: <b>deref_parm_in_call</b>: Function "dma_memory_rw_relaxed(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:121:5: <b>cond_false</b>: Condition "!dma_has_iommu(dma)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:126:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma.h:127:9: <b>deref_parm_in_call</b>: Function "iommu_dma_memory_rw(DMAContext *, dma_addr_t, void *, dma_addr_t, DMADirection)" dereferences "buf".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:318:5: <b>cond_true</b>: Condition "len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/dma-helpers.c:320:9: <b>cond_true</b>: Condition "err", taking true branch</span> qemu-kvm-1.2.0/dma-helpers.c:326:6: <b>deref_parm_in_call</b>: Function "memset(void *, int, size_t)" dereferences "buf". <a name='def837'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def837'>[#def837]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:203: <b>switch</b>: Switch case value "162"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:208: <b>switch_case</b>: Reached case "162"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:208: <b>equality_cond</b>: Jumping to case "162".</span> qemu-kvm-1.2.0/hw/ppc405_uc.c:209: <b>overrun-local</b>: Overrunning array "pob->besr" of 2 4-byte elements at element index 2 (byte offset 8) using index "dcrn - 160" (which evaluates to 2). <a name='def838'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def838'>[#def838]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:225: <b>switch</b>: Switch case value "162"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:230: <b>switch_case</b>: Reached case "162"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/ppc405_uc.c:230: <b>equality_cond</b>: Jumping to case "162".</span> qemu-kvm-1.2.0/hw/ppc405_uc.c:232: <b>overrun-local</b>: Overrunning array "pob->besr" of 2 4-byte elements at element index 2 (byte offset 8) using index "dcrn - 160" (which evaluates to 2). <a name='def839'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def839'>[#def839]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:543: <b>cond_false</b>: Condition "!(env->psw.mask & 0x100000000000000ULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:545: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_false</b>: Condition "env->ext_index < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_at_least</b>: Checking "env->ext_index < 0" implies that the value of "env->ext_index" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_false</b>: Condition "env->ext_index > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:549: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:547: <b>cond_between</b>: Checking "env->ext_index > 16" implies that the value of "env->ext_index" is between 0 and 16 (inclusive) on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-s390x/helper.c:551: <b>alias</b>: Assigning: "q" = "&env->ext_queue[env->ext_index]". "q" may now point between elements 0 and 16 (inclusive) of "env->ext_queue" (which consists of 16 12-byte elements).</span> qemu-kvm-1.2.0/target-s390x/helper.c:554: <b>overrun-local</b>: Overrunning array of 16 12-byte elements at element index 16 (byte offset 192) by dereferencing pointer "q". <a name='def840'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def840'>[#def840]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_true</b>: Condition "r > 15", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:206: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:208: <b>cond_false</b>: Condition "r == 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:210: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:210: <b>cond_false</b>: Condition "r == 3", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:212: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:213: <b>cond_false</b>: Condition "r == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:214: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:215: <b>cond_true</b>: Condition "dc->tb_flags & 512", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:215: <b>cond_false</b>: Condition "r == 15", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:217: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:217: <b>cond_false</b>: Condition "r == 13", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:218: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/target-cris/translate.c:219: <b>overrun-local</b>: Overrunning array "cpu_PR" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). <a name='def841'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def841'>[#def841]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_true</b>: Condition "r > 15", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:169: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> qemu-kvm-1.2.0/target-cris/translate.c:171: <b>overrun-local</b>: Overrunning array "cpu_R" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). <a name='def842'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def842'>[#def842]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2028: <b>switch_case</b>: Reached case "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2029: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 12 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2033: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 12) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def843'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def843'>[#def843]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2028: <b>switch_case</b>: Reached case "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2029: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids > validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2030: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "valids < validd", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2031: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 12 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2034: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 12) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def844'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def844'>[#def844]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2009: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2013: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2013: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 14 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2014: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def845'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def845'>[#def845]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2037: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2038: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_false</b>: Condition "upper - j < validd", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2041: <b>cond_between</b>: Checking "i >= 0" implies that the value of "i" is between 0 and 14 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2042: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "i" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def846'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def846'>[#def846]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2009: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2010: <b>cond_between</b>: Checking "j >= 0" implies that the value of "j" is between 0 and 14 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2012: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "j" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def847'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def847'>[#def847]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "valids < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2006: <b>cond_true</b>: Condition "validd < upper", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2008: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2018: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2019: <b>cond_true</b>: Condition "j >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2019: <b>cond_between</b>: Checking "j >= 0" implies that the value of "j" is between 0 and 14 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:2021: <b>overrun-call</b>: Overrunning callee's array of size 8 by passing argument "j" (which evaluates to 14) in call to "pcmp_val(XMMReg *, uint8_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1982:5: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/ops_sse.h:1985:10: <b>switch_case</b>: Reached case "1"</span> qemu-kvm-1.2.0/target-i386/ops_sse.h:1986:9: <b>index_parm</b>: Indexing "r->_w" with "i". <a name='def848'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def848'>[#def848]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>cond_true</b>: Condition "i < number_of_entries", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:447: <b>cond_true</b>: Condition "i == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:448: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:442: <b>cond_false</b>: Condition "i < number_of_entries", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:448: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>cond_true</b>: Condition "i < 26 * number_of_entries", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_true</b>: Condition "offset < 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:453: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:456: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:449: <b>cond_true</b>: Condition "i < 26 * number_of_entries", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_true</b>: Condition "offset < 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>cond_between</b>: Checking "offset < 10" implies that the value of "offset" is between 0 and 9 (inclusive) on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>assignment</b>: Assigning: "offset" = "1 + offset". The value of "offset" is now between 1 and 10 (inclusive).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:451: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:453: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block/vvfat.c:455: <b>overrun-local</b>: Overrunning array "entry->name" of 8 bytes at byte offset 10 using index "offset" (which evaluates to 10). <a name='def849'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def849'>[#def849]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_true</b>: Condition "is_dot", taking true branch</span> qemu-kvm-1.2.0/block/vvfat.c:622: <b>overrun-buffer-arg</b>: Overrunning array "entry->name" of 8 bytes by passing it to a function which accesses it at byte offset 10 using argument "11UL". <a name='def850'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def850'>[#def850]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:620: <b>cond_false</b>: Condition "is_dot", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:625: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "filename[j] != '.'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>cond_false</b>: Condition "filename[j] != '.'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:630: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:631: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>cond_true</b>: Condition "j > 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:632: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:634: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:640: <b>cond_true</b>: Condition "j > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "filename[j + 1 + i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "filename[j + 1 + i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_true</b>: Condition "i < 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:641: <b>cond_false</b>: Condition "filename[j + 1 + i]", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:642: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i == 10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "entry->name[i] == 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 10", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i == 7", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "entry->name[i] == 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_true</b>: Condition "i > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "entry->name[i] == 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_true</b>: Condition "i >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 10", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>cond_false</b>: Condition "i == 7", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:646: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:647: <b>cond_true</b>: Condition "entry->name[i] <= 32", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:649: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:651: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:645: <b>cond_false</b>: Condition "i >= 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:652: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:655: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_false</b>: Condition "!is_long_name(entry1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_false</b>: Condition "!is_long_name(entry1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:661: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:659: <b>cond_true</b>: Condition "entry1 < entry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block/vvfat.c:660: <b>cond_true</b>: Condition "!is_long_name(entry1)", taking true branch</span> qemu-kvm-1.2.0/block/vvfat.c:660: <b>overrun-buffer-arg</b>: Overrunning array "entry1->name" of 8 bytes by passing it to a function which accesses it at byte offset 10 using argument "11UL". <a name='def851'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def851'>[#def851]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:218: <b>cond_false</b>: Condition "cmdline[0] == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:219: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:221: <b>cond_true</b>: Condition "rs->hist_entry != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:225: <b>cond_false</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:227: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_true</b>: Condition "idx < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:232: <b>cond_false</b>: Condition "hist_entry == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:233: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:234: <b>cond_false</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:246: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:247: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_true</b>: Condition "idx < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:230: <b>cond_at_most</b>: Checking "idx < 64" implies that the value of "idx" may be up to 63 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:232: <b>cond_false</b>: Condition "hist_entry == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:233: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/readline.c:234: <b>cond_true</b>: Condition "__coverity_strcmp(hist_entry, cmdline) == 0", taking true branch</span> qemu-kvm-1.2.0/readline.c:238: <b>overrun-local</b>: Overrunning array of 512 bytes at byte offset 512 by dereferencing pointer "&rs->history[idx + 1]". <a name='def852'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def852'>[#def852]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_true</b>: Condition "f->is_write == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:558: <b>cond_false</b>: Condition "f->buf_index > 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:562: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_true</b>: Condition "f->buf_index >= 32768", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_false</b>: Condition "f->buf_index >= 32768", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:574: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_true</b>: Condition "f->buf_index >= 32768", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:573: <b>cond_at_least</b>: Checking "f->buf_index >= 32768" implies that the value of "f->buf_index" is at least 32768 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:575: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "!f->last_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:564: <b>cond_true</b>: Condition "size > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:566: <b>cond_true</b>: Condition "l > size", taking true branch</span> qemu-kvm-1.2.0/savevm.c:568: <b>overrun-local</b>: Overrunning array of 32768 bytes at byte offset 32768 by dereferencing pointer "&f->buf[f->buf_index]". <a name='def853'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def853'>[#def853]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3428: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3431: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3442: <b>cond_false</b>: Condition "guest_data - arg < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3445: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3450: <b>switch</b>: Switch case value "3241737481U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3473: <b>switch_case</b>: Reached case "3241737481U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3478: <b>overrun-buffer-val</b>: Overrunning array "arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". <a name='def854'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def854'>[#def854]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3251: <b>overrun-buffer-val</b>: Overrunning array "extent_arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". <a name='def855'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def855'>[#def855]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3337: <b>cond_true</b>: Condition "arg_type[0] == TYPE_PTR", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3338: <b>cond_true</b>: Condition "ie->access == (3 /* 1 | 2 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3344: <b>cond_false</b>: Condition "!argptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3345: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:3353: <b>overrun-buffer-val</b>: Overrunning array "ifreq_arg_type" of 8 bytes by passing it to a function which accesses it at byte offset 8.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:88:5: <b>switch</b>: Switch case value "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:133:10: <b>switch_case</b>: Reached case "10"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.h:135:9: <b>index_const</b>: Pointer "type_ptr" indexed by constant "2" through dereference in call to "thunk_type_size_array(argtype const *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/thunk.c:309:5: <b>deref_parm_in_call</b>: Function "thunk_type_size(argtype const *, int)" dereferences "type_ptr".</span> qemu-kvm-1.2.0/thunk.h:87:5: <b>deref_parm</b>: Directly dereferencing parameter "type_ptr". <a name='def856'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def856'>[#def856]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:93: <b>return_constant</b>: Function call "cpu_mmu_index(env)" returns 4.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:93: <b>assignment</b>: Assigning: "mmu_idx" = "cpu_mmu_index(env)". The value of "mmu_idx" is now 4.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:94: <b>cond_true</b>: Condition "!!(env->tlb_table[mmu_idx][page_index].addr_code != (addr & (18446744073709543427UL /* ~((1 << 13) - 1) | 4 - 1 */)))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:94: <b>cond_true</b>: Condition "!!(env->tlb_table[mmu_idx][page_index].addr_code != (addr & (18446744073709543427UL /* ~((1 << 13) - 1) | 4 - 1 */)))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/softmmu_header.h:96: <b>overrun-call</b>: Overrunning callee's array of size 2 by passing argument "mmu_idx" (which evaluates to 4) in call to "helper_ldl_cmmu(struct CPUARMState *, target_ulong, int)".</span> qemu-kvm-1.2.0/softmmu_template.h:108:5: <b>index_parm</b>: Indexing "env->tlb_table" with "mmu_idx". <a name='def857'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def857'>[#def857]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:298: <b>cond_true</b>: Condition "so->so_urgc > 2048", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:299: <b>assignment</b>: Assigning: "so->so_urgc" = "2048".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:301: <b>cond_false</b>: Condition "sb->sb_rptr < sb->sb_wptr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:307: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>cond_false</b>: Condition "len > so->so_urgc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:314: <b>cond_at_most</b>: Checking "len > so->so_urgc" implies that the value of "len" may be up to 2048 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:317: <b>cond_true</b>: Condition "so->so_urgc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/socket.c:319: <b>cond_true</b>: Condition "n > so->so_urgc", taking true branch</span> qemu-kvm-1.2.0/slirp/socket.c:320: <b>overrun-local</b>: Overrunning array of 2048 bytes at byte offset 2048 by dereferencing pointer "&buff[len]". <a name='def858'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def858'>[#def858]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:303: <b>cond_false</b>: Condition "!s->enable", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:304: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "s->in_len >= 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "plen < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "s->in_len >= s->in_hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "plen < s->in_hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_true</b>: Condition "s->in_len >= s->in_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:322: <b>assignment</b>: Assigning: "s->in_data" = "2147483647".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:324: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:325: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:326: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:309: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "s->in_len >= 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:310: <b>cond_true</b>: Condition "plen < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_true</b>: Condition "s->in_len >= s->in_hdr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:313: <b>cond_false</b>: Condition "plen < s->in_hdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:314: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_true</b>: Condition "s->in_len >= s->in_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/bt-hci-csr.c:316: <b>cond_at_least</b>: Checking "s->in_len >= s->in_data" implies that the value of "s->in_len" is at least 2147483647 on the true branch.</span> qemu-kvm-1.2.0/hw/bt-hci-csr.c:319: <b>overrun-local</b>: Overrunning array of 4096 bytes at byte offset 2147483647 by dereferencing pointer "&s->inpkt[s->in_len]". <a name='def859'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def859'>[#def859]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x800", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x80", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x40", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 0x10", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:221: <b>cond_true</b>: Condition "eflags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_true</b>: Condition "i < 6", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_true</b>: Condition "i < 6", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:247: <b>cond_false</b>: Condition "i < 6", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:250: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_true</b>: Condition "i < 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_true</b>: Condition "i < 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:281: <b>cond_false</b>: Condition "i < 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:283: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:287: <b>cond_true</b>: Condition "flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:288: <b>cond_true</b>: Condition "(unsigned int)env->cc_op < CC_OP_NB", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:289: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:291: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:306: <b>cond_true</b>: Condition "flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:310: <b>cond_true</b>: Condition "!env->fptags[i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:310: <b>cond_true</b>: Condition "!env->fptags[i]", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:309: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:311: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:323: <b>cond_false</b>: Condition "(i & 1) == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:326: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_true</b>: Condition "i < 8", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:323: <b>cond_true</b>: Condition "(i & 1) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:324: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:326: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:318: <b>cond_false</b>: Condition "i < 8", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:327: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:328: <b>cond_true</b>: Condition "env->hflags & (32768U /* 1 << 15 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:329: <b>assignment</b>: Assigning: "nb" = "16".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:329: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:331: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_true</b>: Condition "i < nb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:339: <b>cond_false</b>: Condition "(i & 1) == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:342: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:343: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_true</b>: Condition "i < nb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-i386/helper.c:332: <b>cond_at_most</b>: Checking "i < nb" implies that the value of "i" may be up to 15 on the true branch.</span> qemu-kvm-1.2.0/target-i386/helper.c:333: <b>overrun-local</b>: Overrunning array "env->xmm_regs" of 8 16-byte elements at element index 15 (byte offset 240) using index "i" (which evaluates to 15). <a name='def860'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def860'>[#def860]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:221: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:224: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:229: <b>alias</b>: Assigning: "cmsg" = "&msg_control.cmsg". "cmsg" now points to element 0 of "msg_control.cmsg" (which consists of 1 16-byte elements).</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:233: <b>overrun-buffer-arg</b>: Overrunning struct type cmsghdr of 0 bytes by passing it to a function which accesses it at byte offset 3 using argument "4UL". <a name='def861'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def861'>[#def861]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_false</b>: Condition "r < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_at_least</b>: Checking "r < 0" implies that the value of "r" is at least 0 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_true</b>: Condition "r > 15", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-cris/translate.c:175: <b>cond_at_least</b>: Checking "r > 15" implies that the value of "r" is at least 16 on the true branch.</span> qemu-kvm-1.2.0/target-cris/translate.c:177: <b>overrun-local</b>: Overrunning array "cpu_R" of 16 4-byte elements at element index 16 (byte offset 64) using index "r" (which evaluates to 16). <a name='def862'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def862'>[#def862]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_true</b>: Condition "i < 512U /* 64 * 8 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_true</b>: Condition "i < 512U /* 64 * 8 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_at_most</b>: Checking "i < 512U" implies that the value of "i" may be up to 511 on the true branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:421: <b>illegal_address</b>: "&s->output_irq[i]" evaluates to an address that is at byte offset 4088 of an array of 512 bytes.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_combiner.c:420: <b>cond_false</b>: Condition "i < 512U /* 64 * 8 */", taking false branch</span> qemu-kvm-1.2.0/hw/exynos4210_combiner.c:422: <b>loop_end</b>: Reached end of loop <a name='def863'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def863'>[#def863]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:166: <b>cond_true</b>: Condition "invalidate", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:179: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>cond_true</b>: Condition "nextchr == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:182: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:186: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:188: <b>cond_false</b>: Condition "chr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:189: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:193: <b>cond_false</b>: Condition "chr == 410", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:201: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:208: <b>cond_true</b>: Condition "keycode == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:211: <b>cond_true</b>: Condition "nextchr != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:217: <b>cond_true</b>: Condition "keycode != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode >= (1026 /* 2 | 0x400 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode < 1035 /* (2 | 0x400) + 9 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:228: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:296: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:179: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:181: <b>cond_true</b>: Condition "nextchr == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:182: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:186: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:188: <b>cond_false</b>: Condition "chr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:189: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:193: <b>cond_false</b>: Condition "chr == 410", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:201: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:208: <b>cond_true</b>: Condition "keycode == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:211: <b>cond_true</b>: Condition "nextchr != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:217: <b>cond_true</b>: Condition "keycode != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_true</b>: Condition "keycode >= (1026 /* 2 | 0x400 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:221: <b>cond_false</b>: Condition "keycode < 1035 /* (2 | 0x400) + 9 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:229: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:234: <b>cond_true</b>: Condition "kbd_layout", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:236: <b>cond_false</b>: Condition "chr < 511", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:237: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:236: <b>cond_at_least</b>: Checking "chr < 511" implies that the value of "chr" is at least 511 on the false branch.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:239: <b>cond_true</b>: Condition "keysym == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:240: <b>cond_false</b>: Condition "chr < 32", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:246: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:250: <b>cond_false</b>: Condition "keycode == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:251: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:257: <b>cond_false</b>: Condition "keycode == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:258: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:260: <b>cond_false</b>: Condition "is_graphic_console()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/curses.c:289: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/ui/curses.c:290: <b>overrun-local</b>: Overrunning array "curses2qemu" of 511 4-byte elements at element index 511 (byte offset 2044) using index "chr" (which evaluates to 511). <a name='def864'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def864'>[#def864]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:251: <b>cond_true</b>: Condition "fp == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:254: <b>cond_false</b>: Condition "t == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:256: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:262: <b>alias</b>: Assigning: "fp->frag_link.next" = "&fp->frag_link". "fp->frag_link.next" now points to byte 0 of "fp->frag_link" (which consists of 16 bytes).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:266: <b>goto</b>: Jumping to label "insert"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:312: <b>label</b>: Reached label "insert"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>cond_true</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:321: <b>cond_false</b>: Condition "q->ipf_ip.ip_off != next", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:322: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:324: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:319: <b>cond_false</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:324: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:325: <b>cond_false</b>: Condition "((struct ipasfrag *)q->ipf_link.prev)->ipf_ip.ip_tos & 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:326: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:335: <b>cond_false</b>: Condition "q != (struct ipasfrag *)&fp->frag_link", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:339: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:347: <b>alias</b>: Assigning: "q" = "fp->frag_link.next". "q" now points to byte 0 of "fp->frag_link" (which consists of 16 bytes).</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:356: <b>cond_false</b>: Condition "m->m_hdr.mh_flags & 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:359: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_input.c:361: <b>alias</b>: Assigning: "ip" = "(char *)q + 16UL". "ip" now points to byte 16 of "fp->frag_link" (which consists of 16 bytes).</span> qemu-kvm-1.2.0/slirp/ip_input.c:362: <b>overrun-local</b>: Overrunning array of 16 bytes at byte offset 16 by dereferencing pointer "ip". <a name='def865'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def865'>[#def865]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "1568UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:292: <b>switch_case</b>: Reached case "1568UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:292: <b>equality_cond</b>: Jumping to case "1568UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:293: <b>cond_false</b>: Condition "offset == 1540", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:295: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:296: <b>overrun-local</b>: Overrunning array "(*s).ddr" of 8 4-byte elements at element index 8 (byte offset 32) using index "(offset - 1536UL) / 4UL" (which evaluates to 8). <a name='def866'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def866'>[#def866]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "2064UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:299: <b>switch_case</b>: Reached case "2064UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:299: <b>equality_cond</b>: Jumping to case "2064UL".</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:300: <b>overrun-local</b>: Overrunning array "(*s).mio_func" of 4 4-byte elements at element index 4 (byte offset 16) using index "(offset - 2048UL) / 4UL" (which evaluates to 4). <a name='def867'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def867'>[#def867]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "468UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:268: <b>switch_case</b>: Reached case "468UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:268: <b>equality_cond</b>: Jumping to case "468UL".</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:269: <b>overrun-local</b>: Overrunning array "(*s).misc" of 9 4-byte elements at element index 9 (byte offset 36) using index "(offset - 432UL) / 4UL" (which evaluates to 9). <a name='def868'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def868'>[#def868]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:253: <b>switch</b>: Switch case value "600UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:270: <b>switch_case</b>: Reached case "600UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:270: <b>equality_cond</b>: Jumping to case "600UL".</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:271: <b>overrun-local</b>: Overrunning array "(*s).reset" of 22 4-byte elements at element index 22 (byte offset 88) using index "(offset - 512UL) / 4UL" (which evaluates to 22). <a name='def869'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def869'>[#def869]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "1568UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:427: <b>switch_case</b>: Reached case "1568UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:427: <b>equality_cond</b>: Jumping to case "1568UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:428: <b>cond_false</b>: Condition "offset == 1540", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:430: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:431: <b>overrun-local</b>: Overrunning array "(*s).ddr" of 8 4-byte elements at element index 8 (byte offset 32) using index "(offset - 1536UL) / 4UL" (which evaluates to 8). <a name='def870'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def870'>[#def870]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "2064UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:436: <b>switch_case</b>: Reached case "2064UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:436: <b>equality_cond</b>: Jumping to case "2064UL".</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:437: <b>overrun-local</b>: Overrunning array "(*s).mio_func" of 4 4-byte elements at element index 4 (byte offset 16) using index "(offset - 2048UL) / 4UL" (which evaluates to 4). <a name='def871'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def871'>[#def871]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "468UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:391: <b>switch_case</b>: Reached case "468UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:391: <b>equality_cond</b>: Jumping to case "468UL".</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:392: <b>overrun-local</b>: Overrunning array "(*s).misc" of 9 4-byte elements at element index 9 (byte offset 36) using index "(offset - 432UL) / 4UL" (which evaluates to 9). <a name='def872'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def872'>[#def872]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:348: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:375: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:377: <b>cond_true</b>: Condition "!(*s).lockval", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:378: <b>switch</b>: Switch case value "600UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:394: <b>switch_case</b>: Reached case "600UL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:394: <b>equality_cond</b>: Jumping to case "600UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:395: <b>cond_false</b>: Condition "offset == 592", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/zynq_slcr.c:397: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/zynq_slcr.c:398: <b>overrun-local</b>: Overrunning array "(*s).reset" of 22 4-byte elements at element index 22 (byte offset 88) using index "(offset - 512UL) / 4UL" (which evaluates to 22). <a name='def873'/><b>Error: <span style='background: #C0FF00;'>OVERRUN</span>:</b> <a href ='#def873'>[#def873]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>cond_true</b>: Condition "type != 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>cond_false</b>: Condition "type != 11", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:258: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:261: <b>cond_false</b>: Condition "!msrc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:270: <b>cond_false</b>: Condition "ip->ip_off & 0x1fff", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:273: <b>cond_false</b>: Condition "(ip->ip_src.s_addr & __bswap_32(268435455U /* ~(0xf << 28) */)) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:275: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:279: <b>cond_true</b>: Condition "ip->ip_p == IPPROTO_ICMP", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>cond_false</b>: Condition "icp->icmp_type > 18", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>cond_false</b>: Condition "icmp_flush[icp->icmp_type]", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:285: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:290: <b>cond_false</b>: Condition "!m", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:292: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:296: <b>cond_true</b>: Condition "new_m_size > m->m_hdr.mh_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:311: <b>cond_false</b>: Condition "minsize", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:312: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:312: <b>cond_true</b>: Condition "s_ip_len > 548U /* 576 - 28 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/ip_icmp.c:313: <b>assignment</b>: Assigning: "s_ip_len" = "548U".</span> qemu-kvm-1.2.0/slirp/ip_icmp.c:324: <b>overrun-buffer-arg</b>: Overrunning struct type ip of 20 bytes by passing it to a function which accesses it at byte offset 547 using argument "s_ip_len" (which evaluates to 548). <a name='def874'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def874'>[#def874]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1103: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1103: <b>var_assign</b>: Assigning: "sockfd" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1104: <b>cond_false</b>: Condition "sockfd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1107: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1111: <b>noescape</b>: Resource "sockfd" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1111: <b>cond_true</b>: Condition "connect(sockfd, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&helper}), size) < 0", taking true branch</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1113: <b>leaked_handle</b>: Handle variable "sockfd" going out of scope leaks the handle. <a name='def875'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def875'>[#def875]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>var_assign</b>: Assigning: "pidfd" = handle returned from "open(pidfile, 65, 384)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "pidfd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "lockf(pidfd, 2, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:252: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "ftruncate(int, __off64_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "ftruncate(pidfd, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "lseek(int, __off64_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_true</b>: Condition "lseek(pidfd, 0, 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:256: <b>goto</b>: Jumping to label "fail"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:266: <b>label</b>: Reached label "fail"</span> qemu-kvm-1.2.0/qemu-ga.c:268: <b>leaked_handle</b>: Handle variable "pidfd" going out of scope leaks the handle. <a name='def876'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def876'>[#def876]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:245: <b>var_assign</b>: Assigning: "pidfd" = handle returned from "open(pidfile, 65, 384)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "pidfd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:246: <b>cond_false</b>: Condition "lockf(pidfd, 2, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:252: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "ftruncate(int, __off64_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "ftruncate(pidfd, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "lseek(int, __off64_t, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:254: <b>cond_false</b>: Condition "lseek(pidfd, 0, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:257: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:259: <b>noescape</b>: Resource "pidfd" is not freed or pointed-to in function "write(int, void const *, size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:259: <b>cond_false</b>: Condition "write(pidfd, pidstr, strlen(pidstr)) != strlen(pidstr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:262: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-ga.c:264: <b>leaked_handle</b>: Handle variable "pidfd" going out of scope leaks the handle. <a name='def877'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def877'>[#def877]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:131: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:131: <b>var_assign</b>: Assigning: "nullfd" = handle returned from "open("/dev/null", 2)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:132: <b>cond_false</b>: Condition "nullfd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:134: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:136: <b>noescape</b>: Resource "nullfd" is not freed or pointed-to in function "dup2(int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:138: <b>cond_false</b>: Condition "nullfd != fd", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-ga.c:140: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-ga.c:141: <b>leaked_handle</b>: Handle variable "nullfd" going out of scope leaks the handle. <a name='def878'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def878'>[#def878]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2600: <b>switch</b>: Switch case value "13"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2607: <b>switch_case</b>: Reached case "13"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2609: <b>alloc_arg</b>: "target_to_host_semarray(int, unsigned short **, abi_ulong)" allocates memory that is stored into "array".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2539:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2540:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2544:5: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2544:5: <b>var_assign</b>: Assigning: "*host_array" = "malloc(nsems * 2UL)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2547:5: <b>cond_true</b>: Condition "!array", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:2610: <b>cond_true</b>: Condition "err", taking true branch</span> qemu-kvm-1.2.0/linux-user/syscall.c:2611: <b>leaked_storage</b>: Variable "array" going out of scope leaks the storage it points to. <a name='def879'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def879'>[#def879]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:346: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:346: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(filename, 66, 384)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:347: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:349: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:350: <b>cond_false</b>: Condition "lockf(fd, 2, 0) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:353: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:355: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "write(int, void const *, size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:355: <b>cond_false</b>: Condition "write(fd, buffer, len) != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/os-posix.c:358: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/os-posix.c:361: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. <a name='def880'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def880'>[#def880]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_true</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking true branch</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:717: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def881'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def881'>[#def881]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_true</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking true branch</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:721: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def882'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def882'>[#def882]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_true</b>: Condition "listen(sock, 1) < 0", taking true branch</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:725: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def883'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def883'>[#def883]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:728: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:729: <b>cond_true</b>: Condition "client < 0", taking true branch</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:731: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def884'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def884'>[#def884]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:703: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:714: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&proxy}), 110U /* sizeof (struct sockaddr_un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:718: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:719: <b>cond_false</b>: Condition "chown(proxy.sun_path, uid, gid) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:722: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:723: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:728: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:729: <b>cond_false</b>: Condition "client < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:732: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:733: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def885'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def885'>[#def885]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>var_assign</b>: Assigning: "interp_name" = storage returned from "malloc(eppnt->p_filesz)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1769: <b>noescape</b>: Resource "interp_name" is not freed or pointed-to in function "memcpy(void * restrict, void const * restrict, size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1777: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1778: <b>cond_true</b>: Condition "interp_name[eppnt->p_filesz - 1] != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1780: <b>goto</b>: Jumping to label "exit_errmsg"</span> qemu-kvm-1.2.0/linux-user/elfload.c:1780: <b>leaked_storage</b>: Variable "interp_name" going out of scope leaks the storage it points to. <a name='def886'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def886'>[#def886]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1724: <b>cond_false</b>: Condition "error == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1726: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1732: <b>cond_true</b>: Condition "vaddr_ef < vaddr_em", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1737: <b>cond_true</b>: Condition "elf_prot & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1738: <b>cond_true</b>: Condition "vaddr < info->start_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1741: <b>cond_true</b>: Condition "vaddr_ef > info->end_code", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1745: <b>cond_true</b>: Condition "elf_prot & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1746: <b>cond_true</b>: Condition "vaddr < info->start_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1749: <b>cond_true</b>: Condition "vaddr_ef > info->end_data", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1752: <b>cond_true</b>: Condition "vaddr_em > info->brk", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1783: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1784: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>alloc_fn</b>: Storage is returned from allocation function "malloc(size_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>var_assign</b>: Assigning: "interp_name" = storage returned from "malloc(eppnt->p_filesz)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_false</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1772: <b>noescape</b>: Resource "interp_name" is not freed or pointed-to in function "pread(int, void *, size_t, __off64_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1774: <b>cond_true</b>: Condition "retval != eppnt->p_filesz", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1775: <b>goto</b>: Jumping to label "exit_perror"</span> qemu-kvm-1.2.0/linux-user/elfload.c:1775: <b>leaked_storage</b>: Variable "interp_name" going out of scope leaks the storage it points to. <a name='def887'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def887'>[#def887]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_VIRTIO_SERIAL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:129: <b>switch_case</b>: Reached case "GA_CHANNEL_VIRTIO_SERIAL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:130: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:130: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(path, 10242)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:135: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:138: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:147: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:148: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:151: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:152: <b>break</b>: Breaking from switch</span> qemu-kvm-1.2.0/qga/channel-posix.c:152: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. <a name='def888'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def888'>[#def888]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_ISA_SERIAL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:154: <b>switch_case</b>: Reached case "GA_CHANNEL_ISA_SERIAL"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:156: <b>open_fn</b>: Returning handle opened by function "qemu_open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:161:5: <b>cond_false</b>: Condition "strstart(name, "/dev/fdset/", &fdset_id_str)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:189:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:192:5: <b>cond_true</b>: Condition "flags & 0x40", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:201:5: <b>var_assign</b>: Assigning: "ret" = "open(name, flags | 0x80000, mode)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:209:5: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:156: <b>var_assign</b>: Assigning: "fd" = handle returned from "qemu_open(path, 2306)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:157: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:160: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:161: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcgetattr(int, struct termios *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:175: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcflush(int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:176: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "tcsetattr(int, int, struct termios const *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:177: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:178: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:180: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:181: <b>break</b>: Breaking from switch</span> qemu-kvm-1.2.0/qga/channel-posix.c:181: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. <a name='def889'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def889'>[#def889]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:128: <b>switch</b>: Switch case value "GA_CHANNEL_UNIX_LISTEN"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:183: <b>switch_case</b>: Reached case "GA_CHANNEL_UNIX_LISTEN"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:184: <b>open_fn</b>: Returning handle opened by function "unix_listen(char const *, char *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:744:5: <b>cond_false</b>: Condition "optstr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:752:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:756:5: <b>open_fn</b>: Returning handle opened by function "unix_listen_opts(QemuOpts *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:663:5: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:663:5: <b>var_assign</b>: Assigning: "sock" = "qemu_socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664:5: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671:5: <b>cond_false</b>: Condition "path", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675:9: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:689:5: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "bind(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:689:5: <b>cond_false</b>: Condition "bind(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&un}), 110U /* sizeof (un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:692:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:693:5: <b>cond_false</b>: Condition "listen(sock, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:696:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:698:5: <b>return_handle</b>: Returning opened handle "sock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:756:5: <b>var_assign</b>: Assigning: "sock" = "unix_listen_opts(opts)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:758:5: <b>cond_true</b>: Condition "sock != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:758:5: <b>cond_true</b>: Condition "ostr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:759:9: <b>cond_false</b>: Condition "optstr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:761:5: <b>return_handle</b>: Returning opened handle "sock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:184: <b>var_assign</b>: Assigning: "fd" = handle returned from "unix_listen(path, NULL, strlen(path))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:185: <b>cond_false</b>: Condition "fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:188: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:189: <b>noescape</b>: Resource "fd" is not freed or pointed-to in function "ga_channel_listen_add(GAChannel *, int, bool)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:55:53: <b>noescape</b>: "ga_channel_listen_add(GAChannel *, int, bool)" does not free or save its handle parameter "listen_fd".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:190: <b>break</b>: Breaking from switch</span> qemu-kvm-1.2.0/qga/channel-posix.c:190: <b>leaked_handle</b>: Handle variable "fd" going out of scope leaks the handle. <a name='def890'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def890'>[#def890]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "channel != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>cond_true</b>: Condition "({...})", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:31: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:33: <b>open_fn</b>: Returning handle opened by function "qemu_accept(int, struct sockaddr *, socklen_t *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:294:5: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:294:5: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:296:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:298:5: <b>open_fn</b>: Returning handle opened by function "accept(int, __SOCKADDR_ARG, socklen_t * restrict)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:298:5: <b>var_assign</b>: Assigning: "ret" = "accept(s, __SOCKADDR_ARG({ .__sockaddr__ = addr}), addrlen)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:299:5: <b>cond_true</b>: Condition "ret >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:300:9: <b>noescape</b>: Resource "ret" is not freed or pointed-to in function "qemu_set_cloexec(int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:157:27: <b>noescape</b>: "qemu_set_cloexec(int)" does not free or save its handle parameter "fd".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:303:5: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:33: <b>var_assign</b>: Assigning: "client_fd" = handle returned from "qemu_accept(g_io_channel_unix_get_fd(channel), (struct sockaddr *)&addr, &addrlen)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:35: <b>cond_false</b>: Condition "client_fd == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:38: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:39: <b>noescape</b>: Resource "client_fd" is not freed or pointed-to in function "fcntl(int, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:40: <b>noescape</b>: Resource "client_fd" is not freed or pointed-to in function "ga_channel_client_add(GAChannel *, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:103:52: <b>noescape</b>: "ga_channel_client_add(GAChannel *, int)" does not free or save its handle parameter "fd".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:41: <b>cond_false</b>: Condition "ret", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:44: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/channel-posix.c:49: <b>cond_false</b>: Condition "!accepted", taking false branch</span> qemu-kvm-1.2.0/qga/channel-posix.c:49: <b>leaked_handle</b>: Handle variable "client_fd" going out of scope leaks the handle. <a name='def891'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def891'>[#def891]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:220: <b>open_fn</b>: Returning handle opened by function "unix_socket_outgoing(char const *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:192:5: <b>open_fn</b>: Returning handle opened by function "unix_connect(char const *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:771:5: <b>open_fn</b>: Returning handle opened by function "unix_connect_opts(QemuOpts *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:711:5: <b>cond_false</b>: Condition "NULL == path", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:714:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:716:5: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:716:5: <b>var_assign</b>: Assigning: "sock" = "qemu_socket(1, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:717:5: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:720:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:725:5: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:725:5: <b>cond_false</b>: Condition "connect(sock, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&un}), 110U /* sizeof (un) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:729:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:731:5: <b>return_handle</b>: Returning opened handle "sock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:771:5: <b>var_assign</b>: Assigning: "sock" = "unix_connect_opts(opts)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:773:5: <b>return_handle</b>: Returning opened handle "sock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:192:5: <b>return_handle_fn</b>: Directly returning handle opened by "unix_connect(char const *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:220: <b>var_assign</b>: Assigning: "sock" = handle returned from "unix_socket_outgoing(sockpath)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:221: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:223: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:225: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "nbd_receive_negotiate(int, char const *, uint32_t *, off_t *, size_t *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:246:31: <b>noescape</b>: "nbd_receive_negotiate(int, char const *, uint32_t *, off_t *, size_t *)" does not free or save its handle parameter "csock".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:227: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:228: <b>goto</b>: Jumping to label "out"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-nbd.c:262: <b>label</b>: Reached label "out"</span> qemu-kvm-1.2.0/qemu-nbd.c:264: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def892'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def892'>[#def892]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:128: <b>cond_false</b>: Condition "do_pty == 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:130: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "(s = qemu_socket(2, SOCK_STREAM, 0)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "bind(s, __CONST_SOCKADDR_ARG({ .__sockaddr__ = (struct sockaddr *)&addr}), addrlen) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:135: <b>cond_false</b>: Condition "listen(s, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:146: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:152: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>open_fn</b>: Returning handle opened by function "qemu_socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:272:5: <b>var_assign</b>: Assigning: "ret" = "socket(domain, type | 0x80000, protocol)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:273:5: <b>cond_true</b>: Condition "ret != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/osdep.c:274:9: <b>return_handle</b>: Returning opened handle "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:162: <b>var_assign</b>: Assigning: "s" = handle returned from "qemu_socket(2, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:165: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "connect(int, __CONST_SOCKADDR_ARG, socklen_t)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:166: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:168: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:169: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/misc.c:170: <b>noescape</b>: Resource "s" is not freed or pointed-to in function "dup2(int, int)".</span> qemu-kvm-1.2.0/slirp/misc.c:171: <b>overwrite_var</b>: Overwriting handle "s" in "s = getdtablesize() - 1" leaks the handle. <a name='def893'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def893'>[#def893]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_false</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:839: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:843: <b>cond_false</b>: Condition "asprintf(&info->value->hardware_address, "%02x:%02x:%02x:%02x:%02x:%02x", (int)mac_addr[0], (int)mac_addr[1], (int)mac_addr[2], (int)mac_addr[3], (int)mac_addr[4], (int)mac_addr[5]) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:852: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:858: <b>cond_true</b>: Condition "ifa->ifa_addr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:858: <b>cond_true</b>: Condition "ifa->ifa_addr->sa_family == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:864: <b>cond_false</b>: Condition "!inet_ntop(2, p, addr4, 16U /* sizeof (addr4) */)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:869: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:874: <b>cond_true</b>: Condition "ifa->ifa_netmask", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:880: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:906: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:908: <b>cond_false</b>: Condition "!address_item", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:910: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "*address_list", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "(*address_list)->next", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:916: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_true</b>: Condition "*address_list", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:914: <b>cond_false</b>: Condition "(*address_list)->next", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:916: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:918: <b>cond_false</b>: Condition "!*address_list", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:920: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_false</b>: Condition "!info", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:817: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(2, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "ioctl(int, unsigned long, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_true</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>goto</b>: Jumping to label "error"</span> qemu-kvm-1.2.0/qga/commands-posix.c:838: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def894'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def894'>[#def894]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:785: <b>cond_false</b>: Condition "getifaddrs(&ifap) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:790: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:792: <b>cond_true</b>: Condition "ifa", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:806: <b>cond_true</b>: Condition "!info", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:811: <b>cond_true</b>: Condition "!cur_item", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:813: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:816: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "!info->value->has_hardware_address", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:819: <b>cond_true</b>: Condition "ifa->ifa_flags & 35111", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>open_fn</b>: Returning handle opened by function "socket(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:822: <b>var_assign</b>: Assigning: "sock" = handle returned from "socket(2, 1, 0)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:823: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:828: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>noescape</b>: Resource "sock" is not freed or pointed-to in function "ioctl(int, unsigned long, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:832: <b>cond_false</b>: Condition "ioctl(sock, 35111, &ifr) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:839: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:843: <b>cond_true</b>: Condition "asprintf(&info->value->hardware_address, "%02x:%02x:%02x:%02x:%02x:%02x", (int)mac_addr[0], (int)mac_addr[1], (int)mac_addr[2], (int)mac_addr[3], (int)mac_addr[4], (int)mac_addr[5]) == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qga/commands-posix.c:851: <b>goto</b>: Jumping to label "error"</span> qemu-kvm-1.2.0/qga/commands-posix.c:851: <b>leaked_handle</b>: Handle variable "sock" going out of scope leaks the handle. <a name='def895'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def895'>[#def895]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:173: <b>switch</b>: Switch case value "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:177: <b>switch_case</b>: Reached case "2"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:178: <b>cond_false</b>: Condition "use_gdb_syscalls()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:182: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:183: <b>cond_false</b>: Condition "!(p = lock_user_string(({...})))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:186: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:187: <b>var_assign</b>: Assigning: "result" = handle returned from "open(p, translate_openflags(({...})), ({...}))".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:188: <b>cond_false</b>: Condition "__hptr = lock_user(0, __gaddr, 4L /* sizeof (abi_ulong) */, 1)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:188: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:191: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:404: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:406: <b>cond_false</b>: Condition "__hptr = lock_user(1, __gaddr, 4L /* sizeof (uint32_t) */, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:406: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:407: <b>cond_false</b>: Condition "__hptr = lock_user(1, __gaddr, 4L /* sizeof (uint32_t) */, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/target-m68k/m68k-semi.c:407: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/target-m68k/m68k-semi.c:408: <b>leaked_handle</b>: Handle variable "result" going out of scope leaks the handle. <a name='def896'/><b>Error: <span style='background: #C0FF00;'>RESOURCE_LEAK</span> (CWE-404):</b> <a href ='#def896'>[#def896]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:104: <b>switch</b>: Switch case value "5"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:113: <b>switch_case</b>: Reached case "5"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/m68k-sim.c:114: <b>open_fn</b>: Returning handle opened by function "open(char const *, int, ...)".</span> qemu-kvm-1.2.0/linux-user/m68k-sim.c:114: <b>leaked_handle</b>: Ignoring handle opened by "open((char *)(unsigned long)tswap32(args[0]), translate_openflags(tswap32(args[1])), tswap32(args[2]))" leaks it. <a name='def897'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def897'>[#def897]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/spapr_pci.c:68: <b>deref_ptr</b>: Directly dereferencing pointer "phb".</span> qemu-kvm-1.2.0/hw/spapr_pci.c:72: <b>check_after_deref</b>: Null-checking "phb" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def898'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def898'>[#def898]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:2722: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->chr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:482:5: <b>deref_parm_in_call</b>: Function "put_packet_binary(GDBState *, char const *, int)" dereferences "s->chr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:446:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_true</b>: Condition "i < len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_true</b>: Condition "i < len", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:452:9: <b>cond_false</b>: Condition "i < len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:454:9: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:460:9: <b>deref_parm_in_call</b>: Function "put_buffer(GDBState *, uint8_t const *, int)" dereferences "s->chr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/gdbstub.c:393:5: <b>deref_parm_in_call</b>: Function "qemu_chr_fe_write(CharDriverState *, uint8_t const *, int)" dereferences "s->chr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:160:5: <b>deref_parm</b>: Directly dereferencing parameter "s".</span> qemu-kvm-1.2.0/gdbstub.c:2725: <b>check_after_deref</b>: Null-checking "s->chr" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def899'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def899'>[#def899]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/exynos4210_fimd.c:1252: <b>deref_ptr</b>: Directly dereferencing pointer "s".</span> qemu-kvm-1.2.0/hw/exynos4210_fimd.c:1256: <b>check_after_deref</b>: Null-checking "s" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def900'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def900'>[#def900]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:446: <b>deref_ptr</b>: Directly dereferencing pointer "peer".</span> qemu-kvm-1.2.0/qemu-sockets.c:508: <b>check_after_deref</b>: Null-checking "peer" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def901'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def901'>[#def901]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/dev-storage.c:432: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->req".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/scsi-bus.c:692:5: <b>deref_parm</b>: Directly dereferencing parameter "req".</span> qemu-kvm-1.2.0/hw/usb/dev-storage.c:433: <b>check_after_deref</b>: Null-checking "s->req" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def902'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def902'>[#def902]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/migration.c:286: <b>deref_ptr_in_call</b>: Dereferencing pointer "s->file".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/savevm.c:551:5: <b>deref_parm</b>: Directly dereferencing parameter "f".</span> qemu-kvm-1.2.0/migration.c:287: <b>check_after_deref</b>: Null-checking "s->file" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def903'/><b>Error: <span style='background: #C0FF00;'>REVERSE_INULL</span> (CWE-476):</b> <a href ='#def903'>[#def903]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/ui/keymaps.c:131: <b>deref_ptr_in_call</b>: Dereferencing pointer "rest".</span> qemu-kvm-1.2.0/ui/keymaps.c:133: <b>check_after_deref</b>: Null-checking "rest" suggests that it may be null, but it has already been dereferenced on all paths leading to the check. <a name='def904'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def904'>[#def904]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:430: <b>cond_true</b>: Condition "!tmpdir", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:432: <b>cond_false</b>: Condition "snprintf(filename, size, "%s/vl.XXXXXX", tmpdir) >= size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/block.c:434: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/block.c:435: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. <a name='def905'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def905'>[#def905]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2375: <b>cond_false</b>: Condition "!hpagesize", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2377: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2379: <b>cond_false</b>: Condition "memory < hpagesize", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2383: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2388: <b>cond_false</b>: Condition "asprintf(&filename, "%s/qemu_back_mem.XXXXXX", path) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/exec.c:2390: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/exec.c:2392: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. <a name='def906'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def906'>[#def906]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5052: <b>cond_true</b>: Condition "fake_open->filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5053: <b>cond_true</b>: Condition "!__coverity_strncmp(pathname, fake_open->filename, strlen(fake_open->filename))", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5055: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5057: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5059: <b>cond_true</b>: Condition "fake_open->filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5066: <b>cond_true</b>: Condition "!tmpdir", taking true branch</span> qemu-kvm-1.2.0/linux-user/syscall.c:5069: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. <a name='def907'/><b>Error: <span style='background: #C0FF00;'>SECURE_TEMP</span> (CWE-377):</b> <a href ='#def907'>[#def907]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:664: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_true</b>: Condition "path", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:671: <b>cond_false</b>: Condition "strlen(path)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:673: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-sockets.c:675: <b>cond_true</b>: Condition "tmpdir", taking true branch</span> qemu-kvm-1.2.0/qemu-sockets.c:684: <b>secure_temp</b>: Calling "mkstemp(char *)" without securely setting umask first. <a name='def908'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def908'>[#def908]</a> qemu-kvm-1.2.0/hw/omap_dma.c:1267: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def909'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def909'>[#def909]</a> qemu-kvm-1.2.0/hw/omap_dma.c:1277: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def910'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def910'>[#def910]</a> qemu-kvm-1.2.0/hw/omap_dma.c:1287: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def911'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def911'>[#def911]</a> qemu-kvm-1.2.0/hw/omap_dma.c:1297: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def912'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def912'>[#def912]</a> qemu-kvm-1.2.0/hw/omap_dma.c:1045: <b>sign_extension</b>: Suspicious implicit sign extension: "value" with type "unsigned short" (16 bits, unsigned) is promoted in "value << 16" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "value << 16" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def913'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def913'>[#def913]</a> qemu-kvm-1.2.0/hw/omap1.c:2704: <b>sign_extension</b>: Suspicious implicit sign extension: "from_bcd(value)" with type "unsigned char" (8 bits, unsigned) is promoted in "from_bcd(value) * 31536000" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "from_bcd(value) * 31536000" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def914'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def914'>[#def914]</a> qemu-kvm-1.2.0/hw/dp8393x.c:204: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[38]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[38]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def915'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def915'>[#def915]</a> qemu-kvm-1.2.0/hw/dp8393x.c:223: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[38]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[38]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def916'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def916'>[#def916]</a> qemu-kvm-1.2.0/hw/dp8393x.c:243: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[20]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[20] << 16) | s->regs[23]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[20] << 16) | s->regs[23]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def917'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def917'>[#def917]</a> qemu-kvm-1.2.0/hw/dp8393x.c:381: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[11]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[11] << 16) | s->regs[10]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[11] << 16) | s->regs[10]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def918'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def918'>[#def918]</a> qemu-kvm-1.2.0/hw/dp8393x.c:355: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def919'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def919'>[#def919]</a> qemu-kvm-1.2.0/hw/dp8393x.c:390: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def920'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def920'>[#def920]</a> qemu-kvm-1.2.0/hw/dp8393x.c:424: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def921'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def921'>[#def921]</a> qemu-kvm-1.2.0/hw/dp8393x.c:431: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[6]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[6] << 16) | s->regs[32]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[6] << 16) | s->regs[32]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def922'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def922'>[#def922]</a> qemu-kvm-1.2.0/hw/megasas.c:391: <b>sign_extension</b>: Suspicious implicit sign extension: "id" with type "unsigned short" (16 bits, unsigned) is promoted in "id << 24" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "id << 24" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def923'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def923'>[#def923]</a> qemu-kvm-1.2.0/hw/fdc.c:136: <b>sign_extension</b>: Suspicious implicit sign extension: "parse->last_sect" with type "unsigned char" (8 bits, unsigned) is promoted in "(parse->max_head + 1) * parse->max_track * parse->last_sect" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(parse->max_head + 1) * parse->max_track * parse->last_sect" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def924'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def924'>[#def924]</a> qemu-kvm-1.2.0/cris-dis.c:2114: <b>sign_extension</b>: Suspicious implicit sign extension: "buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def925'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def925'>[#def925]</a> qemu-kvm-1.2.0/cris-dis.c:2331: <b>sign_extension</b>: Suspicious implicit sign extension: "prefix_buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def926'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def926'>[#def926]</a> qemu-kvm-1.2.0/cris-dis.c:2025: <b>sign_extension</b>: Suspicious implicit sign extension: "buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "buffer[2] + buffer[3] * 256 + buffer[4] * 65536 + buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def927'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def927'>[#def927]</a> qemu-kvm-1.2.0/cris-dis.c:2217: <b>sign_extension</b>: Suspicious implicit sign extension: "prefix_buffer[5]" with type "unsigned char" (8 bits, unsigned) is promoted in "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "prefix_buffer[2] + prefix_buffer[3] * 256 + prefix_buffer[4] * 65536 + prefix_buffer[5] * 16777216" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def928'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def928'>[#def928]</a> qemu-kvm-1.2.0/m68k-dis.c:4693: <b>sign_extension</b>: Suspicious implicit sign extension: "data[cur_byte]" with type "unsigned char" (8 bits, unsigned) is promoted in "data[cur_byte] << cur_bitshift" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "data[cur_byte] << cur_bitshift" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def929'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def929'>[#def929]</a> qemu-kvm-1.2.0/hw/lan9118.c:1159: <b>sign_extension</b>: Suspicious implicit sign extension: "s->write_word_h" with type "unsigned short" (16 bits, unsigned) is promoted in "s->write_word_l + (s->write_word_h << 16)" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "s->write_word_l + (s->write_word_h << 16)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def930'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def930'>[#def930]</a> qemu-kvm-1.2.0/hw/qxl-render.c:199: <b>sign_extension</b>: Suspicious implicit sign extension: "cursor->header.height" with type "unsigned short" (16 bits, unsigned) is promoted in "cursor->header.width * cursor->header.height" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "cursor->header.width * cursor->header.height" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def931'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def931'>[#def931]</a> qemu-kvm-1.2.0/hw/qxl-render.c:199: <b>sign_extension</b>: Suspicious implicit sign extension: "cursor->header.width" with type "unsigned short" (16 bits, unsigned) is promoted in "cursor->header.width * cursor->header.height" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "cursor->header.width * cursor->header.height" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def932'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def932'>[#def932]</a> qemu-kvm-1.2.0/hw/mcf_fec.c:235: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "(s->conf.macaddr.a[0] << 24) | (s->conf.macaddr.a[1] << 16) | (s->conf.macaddr.a[2] << 8) | s->conf.macaddr.a[3]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->conf.macaddr.a[0] << 24) | (s->conf.macaddr.a[1] << 16) | (s->conf.macaddr.a[2] << 8) | s->conf.macaddr.a[3]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def933'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def933'>[#def933]</a> qemu-kvm-1.2.0/hw/mcf_fec.c:239: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[4]" with type "unsigned char" (8 bits, unsigned) is promoted in "(s->conf.macaddr.a[4] << 24) | (s->conf.macaddr.a[5] << 16) | 0x8808" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->conf.macaddr.a[4] << 24) | (s->conf.macaddr.a[5] << 16) | 0x8808" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def934'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def934'>[#def934]</a> qemu-kvm-1.2.0/hw/stellaris_enet.c:173: <b>sign_extension</b>: Suspicious implicit sign extension: "s->conf.macaddr.a[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "s->conf.macaddr.a[0] | (s->conf.macaddr.a[1] << 8) | (s->conf.macaddr.a[2] << 16) | (s->conf.macaddr.a[3] << 24)" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "s->conf.macaddr.a[0] | (s->conf.macaddr.a[1] << 8) | (s->conf.macaddr.a[2] << 16) | (s->conf.macaddr.a[3] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def935'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def935'>[#def935]</a> qemu-kvm-1.2.0/arm-dis.c:4041: <b>sign_extension</b>: Suspicious implicit sign extension: "b[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "b[3] | (b[2] << 8) | (b[1] << 16) | (b[0] << 24)" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "b[3] | (b[2] << 8) | (b[1] << 16) | (b[0] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def936'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def936'>[#def936]</a> qemu-kvm-1.2.0/arm-dis.c:4039: <b>sign_extension</b>: Suspicious implicit sign extension: "b[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "b[0] | (b[1] << 8) | (b[2] << 16) | (b[3] << 24)" to type "int" (32 bits, signed), then sign-extended to type "long" (64 bits, signed). If "b[0] | (b[1] << 8) | (b[2] << 16) | (b[3] << 24)" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def937'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def937'>[#def937]</a> qemu-kvm-1.2.0/microblaze-dis.c:773: <b>sign_extension</b>: Suspicious implicit sign extension: "ibytes[0]" with type "unsigned char" (8 bits, unsigned) is promoted in "(ibytes[0] << 24) | (ibytes[1] << 16) | (ibytes[2] << 8) | ibytes[3]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(ibytes[0] << 24) | (ibytes[1] << 16) | (ibytes[2] << 8) | ibytes[3]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def938'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def938'>[#def938]</a> qemu-kvm-1.2.0/microblaze-dis.c:775: <b>sign_extension</b>: Suspicious implicit sign extension: "ibytes[3]" with type "unsigned char" (8 bits, unsigned) is promoted in "(ibytes[3] << 24) | (ibytes[2] << 16) | (ibytes[1] << 8) | ibytes[0]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(ibytes[3] << 24) | (ibytes[2] << 16) | (ibytes[1] << 8) | ibytes[0]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def939'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def939'>[#def939]</a> qemu-kvm-1.2.0/hw/dp8393x.c:751: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def940'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def940'>[#def940]</a> qemu-kvm-1.2.0/hw/dp8393x.c:805: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def941'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def941'>[#def941]</a> qemu-kvm-1.2.0/hw/dp8393x.c:809: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def942'/><b>Error: <span style='background: #C0FF00;'>SIGN_EXTENSION</span> (CWE-194):</b> <a href ='#def942'>[#def942]</a> qemu-kvm-1.2.0/hw/dp8393x.c:818: <b>sign_extension</b>: Suspicious implicit sign extension: "s->regs[13]" with type "unsigned short" (16 bits, unsigned) is promoted in "(s->regs[13] << 16) | s->regs[14]" to type "int" (32 bits, signed), then sign-extended to type "unsigned long" (64 bits, unsigned). If "(s->regs[13] << 16) | s->regs[14]" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1. <a name='def943'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def943'>[#def943]</a> qemu-kvm-1.2.0/target-ppc/translate_init.c:9649: <b>suspicious_sizeof</b>: Passing argument "1024UL /* 32 * sizeof (opc_handler_t) */" to function "malloc(size_t)" and then casting the return value to "opc_handler_t **" is suspicious. <a name='def944'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def944'>[#def944]</a> qemu-kvm-1.2.0/block/vvfat.c:2849: <b>suspicious_sizeof</b>: Passing argument "8UL /* sizeof (void *) */" to function "g_malloc(gsize)" which returns a value of type "void *" is suspicious. <a name='def945'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def945'>[#def945]</a> qemu-kvm-1.2.0/hw/qxl.c:238: <b>suspicious_sizeof</b>: Passing argument "qxl->guest_surfaces.cmds" of type "QXLPHYSICAL *" and argument "8UL /* sizeof (qxl->guest_surfaces.cmds) */ * qxl->ssd.num_surfaces" to function "memset(void *, int, size_t)" is suspicious. Did you intend to use "sizeof(*qxl->guest_surfaces.cmds)" instead of "sizeof (qxl->guest_surfaces.cmds)" ? In this particular case sizeof(QXLPHYSICAL *) happens to be equal to sizeof(QXLPHYSICAL), but this is not a portable assumption. <a name='def946'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def946'>[#def946]</a> qemu-kvm-1.2.0/hw/qxl.c:952: <b>suspicious_sizeof</b>: Passing argument "caps" of type "uint8_t *" and argument "8UL /* sizeof (caps) */" to function "memcpy(void * restrict, void const * restrict, size_t)" is suspicious. <a name='def947'/><b>Error: <span style='background: #C0FF00;'>SIZEOF_MISMATCH</span> (CWE-569):</b> <a href ='#def947'>[#def947]</a> qemu-kvm-1.2.0/hw/qxl.c:954: <b>suspicious_sizeof</b>: Passing argument "caps" of type "uint8_t *" and argument "8UL /* sizeof (caps) */" to function "memcpy(void * restrict, void const * restrict, size_t)" is suspicious. <a name='def948'/><b>Error: <span style='background: #C0FF00;'>STRING_NULL</span> (CWE-170):</b> <a href ='#def948'>[#def948]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:781: <b>string_null_argument</b>: Function "readlink(char const * restrict, char * restrict, size_t)" does not terminate string "*driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:782: <b>cond_false</b>: Condition "r <= 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:782: <b>cond_false</b>: Condition "r >= 4096UL /* sizeof (driver) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:784: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:786: <b>string_null</b>: Passing unterminated string "driver" to "strrchr(char const *, int)", which expects a null-terminated string. <a name='def949'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def949'>[#def949]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1104: <b>cond_false</b>: Condition "sockfd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1107: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1108: <b>fixed_size_dest</b>: You might overrun the 108 byte fixed-size string "helper.sun_path" by copying "path" without checking the length.</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-proxy.c:1108: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. <a name='def950'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def950'>[#def950]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_true</b>: Condition "modrm.rm", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6219: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> qemu-kvm-1.2.0/i386-dis.c:6220: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[0]" by copying "names[0]" without checking the length. <a name='def951'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def951'>[#def951]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_false</b>: Condition "modrm.rm", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6223: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6226: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6229: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6233: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6234: <b>cond_true</b>: Condition "address_mode != mode_32bit", taking true branch</span> qemu-kvm-1.2.0/i386-dis.c:6238: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[0]" by copying "op1_names[0]" without checking the length. <a name='def952'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def952'>[#def952]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_true</b>: Condition "modrm.rm", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6219: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6221: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6242: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> qemu-kvm-1.2.0/i386-dis.c:6244: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[1]" by copying "names[1]" without checking the length. <a name='def953'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def953'>[#def953]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.mod == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.reg == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6193: <b>cond_true</b>: Condition "modrm.rm <= 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6202: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "prefixes & 0x400", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "olen >= 11UL /* 4 + 7 */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "*(p - 1) == ' '", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 7, "addr", 4) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6206: <b>cond_true</b>: Condition "__coverity_strncmp(p - 3, "16", 2) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6215: <b>cond_false</b>: Condition "modrm.rm", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6223: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6226: <b>cond_true</b>: Condition "!intel_syntax", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6229: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6233: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6234: <b>cond_true</b>: Condition "address_mode != mode_32bit", taking true branch</span> qemu-kvm-1.2.0/i386-dis.c:6239: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[2]" by copying "names[2]" without checking the length. <a name='def954'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def954'>[#def954]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6260: <b>switch</b>: Switch case value "216"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6262: <b>switch_case</b>: Reached case "216"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6264: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6289: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6293: <b>cond_true</b>: Condition "*p == 'i'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6296: <b>cond_false</b>: Condition "!(prefixes & 0x400)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6300: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6302: <b>switch</b>: Switch case value "223"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/i386-dis.c:6304: <b>switch_case</b>: Reached case "223"</span> qemu-kvm-1.2.0/i386-dis.c:6305: <b>fixed_size_dest</b>: You might overrun the 100 byte fixed-size string "op_out[1]" by copying "names32[1]" without checking the length. <a name='def955'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def955'>[#def955]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1293: <b>cond_false</b>: Condition "dev->fd != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1295: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1298: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1300: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1305: <b>fixed_size_dest</b>: You might overrun the 16 byte fixed-size string "dev->port" by copying "port" without checking the length.</span> qemu-kvm-1.2.0/hw/usb/host-linux.c:1305: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. <a name='def956'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def956'>[#def956]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "122"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6913: <b>switch_case</b>: Reached case "122"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6918: <b>cond_false</b>: Condition "!(buf = lock_user(1, arg1, 390L /* sizeof (*buf) */, 0))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6919: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6921: <b>cond_true</b>: Condition "!is_error(ret)", taking true branch</span> qemu-kvm-1.2.0/linux-user/syscall.c:6924: <b>fixed_size_dest</b>: You might overrun the 65 byte fixed-size string "buf->machine" by copying the return value of "cpu_to_uname_machine(void *)" without checking the length. <a name='def957'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def957'>[#def957]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106: <b>switch</b>: Switch case value "122"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6913: <b>switch_case</b>: Reached case "122"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6918: <b>cond_false</b>: Condition "!(buf = lock_user(1, arg1, 390L /* sizeof (*buf) */, 0))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6919: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6921: <b>cond_true</b>: Condition "!is_error(ret)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6926: <b>cond_true</b>: Condition "qemu_uname_release", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6926: <b>cond_true</b>: Condition "*qemu_uname_release", taking true branch</span> qemu-kvm-1.2.0/linux-user/syscall.c:6927: <b>fixed_size_dest</b>: You might overrun the 65 byte fixed-size string "buf->release" by copying "qemu_uname_release" without checking the length. <a name='def958'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def958'>[#def958]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1934: <b>cond_true</b>: Condition "*s == 'p'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'm'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'M'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1937: <b>cond_false</b>: Condition "*s == 'z'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1949: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1953: <b>cond_false</b>: Condition "opcodep->match != 3583U /* 255 + 13 * 256 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1954: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1958: <b>cond_true</b>: Condition "opcodep->name[0] == 'j'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1960: <b>cond_true</b>: Condition "__coverity_strncmp(opcodep->name, "jsr", 3UL /* sizeof ("jsr") - 1 */) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1962: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1965: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1972: <b>cond_true</b>: Condition "*s", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:1974: <b>switch</b>: Switch case value "'P'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2500: <b>switch_case</b>: Reached case "'P'"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2505: <b>cond_false</b>: Condition "sregp->name == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2509: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2510: <b>cond_false</b>: Condition "with_reg_prefix", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cris-dis.c:2511: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/cris-dis.c:2512: <b>fixed_size_dest</b>: You might overrun the 62 byte fixed-size string "tp" by copying "sregp->name" without checking the length. <a name='def959'/><b>Error: <span style='background: #C0FF00;'>STRING_OVERFLOW</span> (CWE-120):</b> <a href ='#def959'>[#def959]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:698: <b>cond_false</b>: Condition "!access(path, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:701: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:704: <b>cond_false</b>: Condition "sock < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:707: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:713: <b>fixed_size_dest</b>: You might overrun the 108 byte fixed-size string "proxy.sun_path" by copying "path" without checking the length.</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:713: <b>parameter_as_source</b>: Note: This defect has an elevated risk because the source argument is a parameter of the current function. <a name='def960'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def960'>[#def960]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:448: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:449: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:451: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "hdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:452: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:453: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:457: <b>cond_false</b>: Condition "hdr->ih_magic != 654645590", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:461: <b>cond_false</b>: Condition "hdr->ih_type != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:464: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:466: <b>switch</b>: Switch case value "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:467: <b>switch_case</b>: Reached case "0"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:469: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:475: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:478: <b>cond_true</b>: Condition "is_linux", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:479: <b>cond_true</b>: Condition "hdr->ih_os == 5", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:480: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:482: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:488: <b>tainted_data</b>: Passing tainted variable "hdr->ih_size" to a tainted sink. <a name='def961'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def961'>[#def961]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:194: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "e".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:219: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:220: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:221: <b>tainted_data</b>: Passing tainted variable "e.a_data" to a tainted sink.</span> qemu-kvm-1.2.0/hw/loader.c:97:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "nbytes" to tainted data sink "read(int, void *, size_t)". <a name='def962'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def962'>[#def962]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:191: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:192: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:194: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "e".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:195: <b>cond_false</b>: Condition "size < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:196: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:198: <b>cond_true</b>: Condition "bswap_needed", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:203: <b>switch</b>: Switch case value "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:214: <b>switch_case</b>: Reached case "264U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 263", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_true</b>: Condition "(e.a_info & 65535) == 204", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:215: <b>cond_false</b>: Condition "(((e.a_info & 65535) == 263) ? (((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text : ((((e.a_info & 65535) == 204) ? target_page_size : 0) + e.a_text + target_page_size - 1 & ~(target_page_size - 1))) + e.a_data > max_sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:216: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:217: <b>cond_true</b>: Condition "(e.a_info & 65535) == 267", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:218: <b>tainted_data</b>: Passing tainted variable "e.a_text" to a tainted sink.</span> qemu-kvm-1.2.0/hw/loader.c:97:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "nbytes" to tainted data sink "read(int, void *, size_t)". <a name='def963'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def963'>[#def963]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:124: <b>cond_false</b>: Condition "!syms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:125: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:130: <b>cond_false</b>: Condition "i < nsyms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:149: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:150: <b>cond_false</b>: Condition "nsyms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:159: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:165: <b>cond_false</b>: Condition "symtab->sh_link >= ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:166: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:167: <b>var_assign_var</b>: Assigning: "strtab" = "shdr_table + symtab->sh_link". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:169: <b>tainted_data</b>: Passing tainted variable "strtab->sh_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def964'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def964'>[#def964]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>tainted_data_transitive</b>: Call to function "find_section32(struct elf32_shdr *, int, int)" with tainted argument "shdr_table" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:56:5: <b>cond_true</b>: Condition "i < n", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:57:9: <b>cond_true</b>: Condition "(shdr_table + i).sh_type == type", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:58:13: <b>return_tainted_data</b>: Returning tainted variable "shdr_table + i".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>var_assign</b>: Assigning: "symtab" = "find_section32(struct elf32_shdr *, int, int)", which taints "symtab".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:123: <b>tainted_data</b>: Passing tainted variable "symtab->sh_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def965'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def965'>[#def965]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:237: <b>var_assign_var</b>: Assigning: "size" = "ehdr.e_phnum * 32UL". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data</b>: Passing tainted variable "size" to a tainted sink. <a name='def966'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def966'>[#def966]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:235: <b>tainted_data</b>: Passing tainted variable "ehdr.e_shnum" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "40UL * ehdr->e_shnum" to tainted data sink "load_at(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def967'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def967'>[#def967]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. <a name='def968'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def968'>[#def968]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. <a name='def969'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def969'>[#def969]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def970'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def970'>[#def970]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def971'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def971'>[#def971]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_false</b>: Condition "addr < low", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:288: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def972'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def972'>[#def972]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def973'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def973'>[#def973]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def974'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def974'>[#def974]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def975'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def975'>[#def975]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def976'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def976'>[#def976]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def977'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def977'>[#def977]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def978'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def978'>[#def978]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def979'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def979'>[#def979]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 52UL /* sizeof (ehdr) */) != 52UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0U".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def980'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def980'>[#def980]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_true</b>: Condition "i < ehdr->e_shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:124: <b>cond_false</b>: Condition "!syms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:125: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:130: <b>cond_false</b>: Condition "i < nsyms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:149: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:150: <b>cond_false</b>: Condition "nsyms", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:159: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:165: <b>cond_false</b>: Condition "symtab->sh_link >= ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:166: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:167: <b>var_assign_var</b>: Assigning: "strtab" = "shdr_table + symtab->sh_link". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:169: <b>tainted_data</b>: Passing tainted variable "strtab->sh_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def981'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def981'>[#def981]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>tainted_data_return</b>: Function "load_at(int, int, int)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_argument</b>: Function "read(int, void *, size_t)" taints argument "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:245:5: <b>cond_false</b>: Condition "read(fd, ptr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:248:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:249:5: <b>return_tainted_data</b>: Returning tainted variable "ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109: <b>var_assign</b>: Assigning: "shdr_table" = "load_at(int, int, int)", which taints "shdr_table".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:111: <b>cond_false</b>: Condition "!shdr_table", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:112: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:114: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:115: <b>cond_false</b>: Condition "i < ehdr->e_shnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:117: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>tainted_data_transitive</b>: Call to function "find_section64(struct elf64_shdr *, int, int)" with tainted argument "shdr_table" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:56:5: <b>cond_true</b>: Condition "i < n", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:57:9: <b>cond_true</b>: Condition "(shdr_table + i).sh_type == type", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:58:13: <b>return_tainted_data</b>: Returning tainted variable "shdr_table + i".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:120: <b>var_assign</b>: Assigning: "symtab" = "find_section64(struct elf64_shdr *, int, int)", which taints "symtab".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:121: <b>cond_false</b>: Condition "!symtab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:122: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:123: <b>tainted_data</b>: Passing tainted variable "symtab->sh_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def982'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def982'>[#def982]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:237: <b>var_assign_var</b>: Assigning: "size" = "ehdr.e_phnum * 56UL". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data</b>: Passing tainted variable "size" to a tainted sink. <a name='def983'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def983'>[#def983]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:235: <b>tainted_data</b>: Passing tainted variable "ehdr.e_shnum" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:109:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "64UL * ehdr->e_shnum" to tainted data sink "load_at(int, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:242:5: <b>cond_false</b>: Condition "lseek(fd, offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:243:9: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/loader.c:245:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "size" to tainted data sink "read(int, void *, size_t)". <a name='def984'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def984'>[#def984]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. <a name='def985'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def985'>[#def985]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "ehdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>tainted_data</b>: Using tainted variable "ehdr.e_phnum" as a loop boundary. <a name='def986'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def986'>[#def986]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def987'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def987'>[#def987]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def988'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def988'>[#def988]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_false</b>: Condition "addr < low", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:288: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def989'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def989'>[#def989]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:286: <b>var_assign_var</b>: Compound assignment involving tainted variable "mem_size" to variable "total_size" taints "total_size".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def990'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def990'>[#def990]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def991'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def991'>[#def991]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:287: <b>cond_true</b>: Condition "addr < low", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:289: <b>cond_true</b>: Condition "addr + mem_size > high", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:295: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def992'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def992'>[#def992]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def993'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def993'>[#def993]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def994'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def994'>[#def994]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_true</b>: Condition "must_swab", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:246: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:245: <b>cond_false</b>: Condition "i < ehdr.e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:248: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def995'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def995'>[#def995]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:255: <b>var_assign_var</b>: Assigning: "mem_size" = "ph->p_memsz". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>cond_false</b>: Condition "read(fd, data, ph->p_filesz) != ph->p_filesz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:262: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:266: <b>cond_true</b>: Condition "translate_fn", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:268: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:270: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:275: <b>cond_false</b>: Condition "!translate_fn", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:281: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:284: <b>tainted_data</b>: Passing tainted variable "mem_size" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/loader.c:643:5: <b>var_assign_parm</b>: Assigning: "rom->romsize" = "len". "rom->romsize" is now tainted.</span> qemu-kvm-1.2.0/hw/loader.c:645:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def996'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def996'>[#def996]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:205: <b>cond_false</b>: Condition "read(fd, &ehdr, 64UL /* sizeof (ehdr) */) != 64UL /* sizeof (ehdr) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:206: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:207: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:209: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:211: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:212: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:213: <b>cond_true</b>: Condition "21 != ehdr.e_machine", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:214: <b>cond_false</b>: Condition "20 != ehdr.e_machine", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:215: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:216: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:230: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:232: <b>cond_true</b>: Condition "pentry", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:240: <b>cond_false</b>: Condition "!phdr", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:241: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:242: <b>cond_false</b>: Condition "read(fd, phdr, size) != size", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:243: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:244: <b>cond_false</b>: Condition "must_swab", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:249: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:252: <b>cond_true</b>: Condition "i < ehdr.e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:253: <b>var_assign_var</b>: Assigning: "ph" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:254: <b>cond_true</b>: Condition "ph->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>cond_true</b>: Condition "ph->p_filesz > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:258: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "ph->p_filesz" by "ph->p_filesz > 0UL".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:259: <b>cond_false</b>: Condition "lseek(fd, ph->p_offset, 0) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/elf_ops.h:260: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/elf_ops.h:261: <b>tainted_data</b>: Passing tainted variable "ph->p_filesz" to a tainted sink. <a name='def997'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def997'>[#def997]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1914: <b>var_assign_var</b>: Assigning: "i" = "(shdr + str_idx).sh_size". Both are now tainted.</span> qemu-kvm-1.2.0/linux-user/elfload.c:1915: <b>tainted_data</b>: Passing tainted variable "i" to a tainted sink. <a name='def998'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def998'>[#def998]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1916: <b>cond_false</b>: Condition "!strings", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1916: <b>cond_false</b>: Condition "pread(fd, strings, i, (shdr + str_idx).sh_offset) != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1918: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1920: <b>var_assign_var</b>: Assigning: "i" = "(shdr + sym_idx).sh_size". Both are now tainted.</span> qemu-kvm-1.2.0/linux-user/elfload.c:1921: <b>tainted_data</b>: Passing tainted variable "i" to a tainted sink. <a name='def999'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def999'>[#def999]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "shdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1891: <b>cond_false</b>: Condition "pread(fd, shdr, i, hdr->e_shoff) != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1893: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1896: <b>cond_true</b>: Condition "i < shnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1897: <b>cond_true</b>: Condition "(shdr + i).sh_type == 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1899: <b>var_assign_var</b>: Assigning: "str_idx" = "(shdr + i).sh_link". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1900: <b>goto</b>: Jumping to label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1907: <b>label</b>: Reached label "found"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1910: <b>cond_false</b>: Condition "!s", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1912: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/elfload.c:1914: <b>tainted_data</b>: Using tainted variable "str_idx" as an index to pointer "shdr". <a name='def1000'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1000'>[#def1000]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "146"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7197:10: <b>switch_case</b>: Reached case "146"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7199:23: <b>parm_assign_alias</b>: Assigning: "count" = "arg3", which taints "count".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7203:13: <b>cond_false</b>: Condition "lock_iovec(0, vec, arg2, count, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7204:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:7205:13: <b>data_index</b>: Passing tainted variable "count" to a tainted data index sink. <a name='def1001'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1001'>[#def1001]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "57"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5700:10: <b>switch_case</b>: Reached case "57"</span> qemu-kvm-1.2.0/linux-user/syscall.c:5701:9: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg2" to tainted data sink "setpgid(__pid_t, __pid_t)". <a name='def1002'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1002'>[#def1002]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "37"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5579:10: <b>switch_case</b>: Reached case "37"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5580:9: <b>data_index</b>: Passing tainted variable "arg2" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". <a name='def1003'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1003'>[#def1003]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "146"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7197:10: <b>switch_case</b>: Reached case "146"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7199:23: <b>parm_assign_alias</b>: Assigning: "count" = "arg3", which taints "count".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7203:13: <b>cond_false</b>: Condition "lock_iovec(0, vec, arg2, count, 1) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:7204:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:7205:13: <b>data_index</b>: Passing tainted variable "count" to a tainted data index sink. <a name='def1004'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1004'>[#def1004]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[1]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "57"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5700:10: <b>switch_case</b>: Reached case "57"</span> qemu-kvm-1.2.0/linux-user/syscall.c:5701:9: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg1" to tainted data sink "setpgid(__pid_t, __pid_t)". <a name='def1005'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1005'>[#def1005]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[2]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "37"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5579:10: <b>switch_case</b>: Reached case "37"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5580:9: <b>data_index</b>: Passing tainted variable "arg2" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". <a name='def1006'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1006'>[#def1006]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5153:10: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5154:9: <b>cond_false</b>: Condition "arg3 == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5156:14: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5157:13: <b>cond_false</b>: Condition "!(p = lock_user(1, arg2, arg3, 0))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5158:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/syscall.c:5159:13: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "arg3" to tainted data sink "read(int, void *, size_t)". <a name='def1007'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1007'>[#def1007]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data_return</b>: Function "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(abi_long)", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_data</b>: Passing tainted variable "env->dregs[3]" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "265"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8463:10: <b>switch_case</b>: Reached case "265"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8464:2: <b>data_index</b>: Passing tainted variable "arg3" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>cond_false</b>: Condition "sig >= 65", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:113:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:112:5: <b>upper_bounds</b>: Checking upper bounds of signed scalar "sig" by "sig >= 65".</span> qemu-kvm-1.2.0/linux-user/signal.c:114:5: <b>data_index</b>: Using tainted variable "sig" as an index to array "target_to_host_signal_table". <a name='def1008'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1008'>[#def1008]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "!f", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "!(kernel_size = get_file_size(f))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_true</b>: Condition "8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>tainted_data_argument</b>: Calling function "fread(void * restrict, size_t, size_t, FILE * restrict)" taints argument "header".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_true</b>: Condition "8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:684: <b>cond_false</b>: Condition "fread(header, 1, ((8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size) ? 8192UL /* sizeof (header) / sizeof (header[0]) */ : kernel_size), f) != ((8192UL /* sizeof (header) / sizeof (header[0]) */ < kernel_size) ? 8192UL /* sizeof (header) / sizeof (header[0]) */ : kernel_size)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:690: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:696: <b>cond_true</b>: Condition "ldl_le_p(&header[514]) == 1400005704", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:697: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:705: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:707: <b>cond_true</b>: Condition "protocol < 512", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:712: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:722: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:735: <b>cond_false</b>: Condition "protocol >= 515", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:738: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:740: <b>cond_true</b>: Condition "initrd_max >= max_ram_size - 65536", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:745: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:749: <b>cond_false</b>: Condition "protocol >= 514", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:751: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:758: <b>cond_true</b>: Condition "vmode", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:762: <b>cond_true</b>: Condition "!__coverity_strncmp(vmode, "normal", 6)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:764: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:770: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:778: <b>cond_false</b>: Condition "protocol >= 512", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:779: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:782: <b>cond_false</b>: Condition "protocol >= 513", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:785: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:788: <b>cond_false</b>: Condition "initrd_filename", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:812: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:815: <b>lower_bounds</b>: Casting narrower unsigned "header[497]" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:815: <b>var_assign_var</b>: Assigning: "setup_size" = "header[497]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:816: <b>cond_false</b>: Condition "setup_size == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:817: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:818: <b>var_assign_var</b>: Assigning: "setup_size" = "(setup_size + 1) * 512". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/pc.c:819: <b>var_assign_var</b>: Compound assignment involving tainted variable "setup_size" to variable "kernel_size" taints "kernel_size".</span> qemu-kvm-1.2.0/hw/pc.c:824: <b>tainted_data</b>: Passing tainted variable "setup_size" to a tainted sink. <a name='def1009'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1009'>[#def1009]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:775: <b>cond_false</b>: Condition "!new_brk", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:778: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:779: <b>cond_false</b>: Condition "new_brk < target_original_brk", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:783: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:787: <b>cond_false</b>: Condition "new_brk <= brk_page", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:796: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>tainted_data_return</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_data</b>: Returning tainted variable "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(brk_page, new_alloc_size, 3, 34, 0, 0U)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:805: <b>var_assign</b>: Assigning: "mapped_addr" = "get_errno(abi_long)", which taints "mapped_addr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:809: <b>cond_false</b>: Condition "mapped_addr == brk_page", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:824: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:824: <b>cond_true</b>: Condition "mapped_addr != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:828: <b>tainted_data</b>: Passing tainted variable "mapped_addr" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:643:5: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:644:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:646:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:647:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:653:5: <b>cond_true</b>: Condition "start > real_start", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:653:5: <b>lower_bounds</b>: Checking lower bounds of unsigned scalar "start" by "start > real_start".</span> qemu-kvm-1.2.0/linux-user/mmap.c:656:9: <b>a_loop_bound</b>: Using tainted variable "start" as a loop boundary. <a name='def1010'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1010'>[#def1010]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1011'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1011'>[#def1011]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1012'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1012'>[#def1012]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1013'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1013'>[#def1013]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2783: <b>switch_case</b>: Reached case "80"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2785: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2786: <b>switch_case</b>: Reached case "25"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2787: <b>var_assign_var</b>: Assigning: "keyboard_layout" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2788: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1014'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1014'>[#def1014]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1015'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1015'>[#def1015]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1016'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1016'>[#def1016]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1017'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1017'>[#def1017]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2777: <b>switch_case</b>: Reached case "87"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2778: <b>var_assign_var</b>: Assigning: "bios_name" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2779: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1018'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1018'>[#def1018]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1019'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1019'>[#def1019]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1020'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1020'>[#def1020]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1021'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1021'>[#def1021]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2774: <b>switch_case</b>: Reached case "86"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2775: <b>var_assign_var</b>: Assigning: "data_dir" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2776: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1022'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1022'>[#def1022]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1023'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1023'>[#def1023]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1024'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1024'>[#def1024]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1025'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1025'>[#def1025]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2765: <b>switch_case</b>: Reached case "84"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2766: <b>var_assign_var</b>: Assigning: "log_file" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2767: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1026'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1026'>[#def1026]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1027'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1027'>[#def1027]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1028'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1028'>[#def1028]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1029'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1029'>[#def1029]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2762: <b>switch_case</b>: Reached case "83"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2763: <b>var_assign_var</b>: Assigning: "log_mask" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2764: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1030'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1030'>[#def1030]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1031'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1031'>[#def1031]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1032'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1032'>[#def1032]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1033'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1033'>[#def1033]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2736: <b>switch_case</b>: Reached case "22"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "value < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2742: <b>cond_false</b>: Condition "*end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2745: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2748: <b>cond_false</b>: Condition "ram_size != sz", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2751: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2752: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2754: <b>switch_case</b>: Reached case "23"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2755: <b>var_assign_var</b>: Assigning: "mem_path" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2756: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1034'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1034'>[#def1034]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1035'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1035'>[#def1035]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1036'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1036'>[#def1036]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1037'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1037'>[#def1037]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2703: <b>switch_case</b>: Reached case "60"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2704: <b>var_assign_var</b>: Assigning: "legacy_bootp_filename" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2705: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1038'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1038'>[#def1038]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1039'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1039'>[#def1039]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1040'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1040'>[#def1040]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1041'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1041'>[#def1041]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2700: <b>switch_case</b>: Reached case "59"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2701: <b>var_assign_var</b>: Assigning: "legacy_tftp_prefix" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2702: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1042'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1042'>[#def1042]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1043'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1043'>[#def1043]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1044'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1044'>[#def1044]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2681: <b>switch_case</b>: Reached case "64"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2682: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1045'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1045'>[#def1045]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_false</b>: Condition "!__coverity_strcmp(p, "none")", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2547: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "lba")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2548: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2597: <b>switch_case</b>: Reached case "47"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 90", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_true</b>: Condition "graphic_rotate != 180", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2599: <b>cond_false</b>: Condition "graphic_rotate != 270", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2604: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2605: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2621: <b>switch_case</b>: Reached case "20"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2631: <b>cond_false</b>: Condition "!__coverity_strchr(optarg, 61)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2634: <b>cond_false</b>: Condition "check_params(buf, 33 /* sizeof (buf) */, params, optarg) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2639: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_false</b>: Condition "legacy", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2641: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "order", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2646: <b>cond_true</b>: Condition "!legacy", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2647: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "once", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2655: <b>cond_true</b>: Condition "get_param_value(buf, 33 /* sizeof (buf) */, "menu", optarg)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2657: <b>cond_true</b>: Condition "!__coverity_strcmp(buf, "on")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2659: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2666: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2672: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2686: <b>switch_case</b>: Reached case "63"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2687: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net.c:1035:5: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strcmp(opts_list->name, "net") != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:743:5: <b>cond_false</b>: Condition "__coverity_strncmp(optarg, "channel,", 8UL /* strlen("channel,") */) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:746:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:751:5: <b>cond_false</b>: Condition "slirp_stacks.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:760:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:761:9: <b>data_index</b>: Passing tainted variable "optarg" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:611:5: <b>parm_assign_alias</b>: Assigning: "p" = "config_str", which taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:612:5: <b>cond_true</b>: Condition "legacy_format", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:613:9: <b>cond_false</b>: Condition "get_str_sep(buf, 128 /* sizeof (buf) */, &p, 58) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:615:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:616:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:632:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "*end != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:634:5: <b>cond_false</b>: Condition "port > 65535", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:636:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_true</b>: Condition "strlen(p) > 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:641:5: <b>cond_false</b>: Condition "!__coverity_strncmp(p, "cmd:", 4)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:648:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/slirp.c:649:9: <b>data_index</b>: Passing tainted variable "p" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2949:5: <b>cond_false</b>: Condition "strstart(filename, "chardev:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2951:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2953:5: <b>data_index</b>: Passing tainted variable "filename" to a tainted data index sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2732:5: <b>cond_false</b>: Condition "error_is_set(&local_err)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2736:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>tainted_data_transitive</b>: Call to function "strstart(char const *, char const *, char const **)" with tainted argument "filename" transitively taints "p".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:68:5: <b>var_assign_alias</b>: Assigning: "p" = "str". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_true</b>: Condition "*q != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:71:9: <b>cond_false</b>: Condition "*p != *q", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:72:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:70:5: <b>cond_false</b>: Condition "*q != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:75:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:76:5: <b>cond_true</b>: Condition "ptr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/cutils.c:77:9: <b>parm_assign</b>: Assigning: "*ptr" = "p", which taints "*ptr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2738:5: <b>cond_true</b>: Condition "strstart(filename, "mon:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2739:9: <b>var_assign_alias</b>: Assigning: "filename" = "p". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "null") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "pty") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "msmouse") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "braille") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2743:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "stdio") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2750:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2751:5: <b>cond_false</b>: Condition "strstart(filename, "vc", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2767:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2768:5: <b>cond_false</b>: Condition "__coverity_strcmp(filename, "con:") == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2771:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2772:5: <b>cond_false</b>: Condition "strstart(filename, "COM", NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2776:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2777:5: <b>cond_false</b>: Condition "strstart(filename, "file:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2781:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2782:5: <b>cond_false</b>: Condition "strstart(filename, "pipe:", &p)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2786:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2787:5: <b>cond_true</b>: Condition "strstart(filename, "tcp:", &p)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "host".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "port".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "p" taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2789:9: <b>cond_true</b>: Condition "sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2791:13: <b>cond_false</b>: Condition "sscanf(p, ":%32[^,]%n", port, &pos) < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-char.c:2792:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/qemu-char.c:2797:9: <b>data_index</b>: Using tainted variable "pos" as an index to pointer "p". <a name='def1046'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1046'>[#def1046]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1047'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1047'>[#def1047]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2521: <b>switch_case</b>: Reached case "21"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2523: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2524: <b>switch_case</b>: Reached case "85"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2527: <b>var_assign_var</b>: Assigning: "p" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2529: <b>cond_false</b>: Condition "cyls > 16383", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2531: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2532: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2535: <b>cond_false</b>: Condition "heads > 16", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2536: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2537: <b>cond_false</b>: Condition "*p != ','", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2538: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs < 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2541: <b>cond_false</b>: Condition "secs > 63", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2542: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2543: <b>cond_true</b>: Condition "*p == ','", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2545: <b>cond_true</b>: Condition "!__coverity_strcmp(p, "none")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2546: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2552: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2553: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2557: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2558: <b>cond_false</b>: Condition "hda_opts != NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2570: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2572: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1048'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1048'>[#def1048]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2504: <b>switch_case</b>: Reached case "15"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2505: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "group".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "id".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "arg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:729:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:730:5: <b>cond_false</b>: Condition "rc < 3", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:730:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1049'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1049'>[#def1049]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2385: <b>cond_false</b>: Condition "0 /* !1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2392: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_true</b>: Condition "i < 64", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2414: <b>cond_false</b>: Condition "i < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2417: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2434: <b>tainted_data_transitive</b>: Call to function "lookup_opt(int, char **, char const **, int *)" with tainted argument "argv" transitively taints "optarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2291:5: <b>cond_true</b>: Condition "r[1] == '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2294:5: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2295:9: <b>cond_false</b>: Condition "!popt->name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2298:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2299:9: <b>cond_true</b>: Condition "!__coverity_strcmp(popt->name, r + 1)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2300:13: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2302:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2303:5: <b>cond_true</b>: Condition "popt->flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2304:9: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2307:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2308:9: <b>var_assign_alias</b>: Assigning: "optarg" = "argv[optind++]". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2310:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2312:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2314:5: <b>parm_assign</b>: Assigning: "*poptarg" = "optarg", which taints "*poptarg".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2436: <b>switch_case</b>: Reached case "118"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2438: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case value "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2439: <b>switch_case</b>: Reached case "119"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2441: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2430: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_true</b>: Condition "optind < argc", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2427: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2431: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2435: <b>switch</b>: Switch case default</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2442: <b>switch_default</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2426: <b>cond_false</b>: Condition "optind < argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2444: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2446: <b>cond_false</b>: Condition "defconfig", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2452: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_true</b>: Condition "argv[optind][0] != '-'", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3329: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2470: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2472: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2473: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2475: <b>var_assign_var</b>: Assigning: "cpu_model" = "optarg". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2476: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3328: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:3330: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2456: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2457: <b>cond_false</b>: Condition "optind >= argc", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2458: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2459: <b>cond_false</b>: Condition "argv[optind][0] != '-'", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2461: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2465: <b>cond_false</b>: Condition "!(popt->arch_mask & arch_type)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2468: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2469: <b>switch</b>: Switch case value "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2508: <b>switch_case</b>: Reached case "16"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:2509: <b>tainted_data</b>: Passing tainted variable "optarg" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "driver".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "property".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:759:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "str" taints "offset".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/qemu-config.c:760:5: <b>cond_false</b>: Condition "rc < 2", taking false branch</span> qemu-kvm-1.2.0/qemu-config.c:760:5: <b>data_index</b>: Using tainted variable "offset" as an index to pointer "str". <a name='def1050'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1050'>[#def1050]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 1, 0)" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1310: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1319: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". <a name='def1051'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1051'>[#def1051]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 16, 0)" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1334: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1388: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". <a name='def1052'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1052'>[#def1052]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 7, 0)" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1452: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1463: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". <a name='def1053'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1053'>[#def1053]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 3, 0)" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1481: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1482: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1485: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1487: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1489: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". <a name='def1054'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1054'>[#def1054]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1252: <b>cond_true</b>: Condition "kvm_check_extension(kvm_state, 29)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1253: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1259: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1261: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "pos != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1278: <b>cond_true</b>: Condition "kvm_device_msix_supported(kvm_state)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1282: <b>cond_false</b>: Condition "!check_irqchip_in_kernel()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1284: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1287: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1289: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1311: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1315: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1317: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1335: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1342: <b>cond_true</b>: Condition "version == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1344: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1374: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1376: <b>cond_false</b>: Condition "size == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1384: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1386: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_true</b>: Condition "type != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1392: <b>cond_false</b>: Condition "type != 9", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1398: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1436: <b>cond_false</b>: Condition "version >= 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1449: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1453: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1459: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1461: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1482: <b>cond_true</b>: Condition "pos", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1485: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1487: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>tainted_data_return</b>: Function "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:411:5: <b>cond_false</b>: Condition "(status & 0x10) == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:413:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:415:5: <b>cond_true</b>: Condition "max_cap--", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>tainted_data_return</b>: Function "assigned_dev_pci_read_byte(PCIDevice *, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>tainted_data_return</b>: Function "assigned_dev_pci_read(PCIDevice *, int, int)" returning tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:351:5: <b>tainted_data_argument</b>: Function "pread(int, void *, size_t, __off64_t)" taints argument "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:352:5: <b>cond_false</b>: Condition "ret != len", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:358:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:360:5: <b>return_tainted_data</b>: Returning tainted variable "val".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:365:5: <b>return_tainted_data_fn</b>: Returning tainted result of "assigned_dev_pci_read(PCIDevice *, int, int)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:416:9: <b>var_assign</b>: Assigning: "pos" = "assigned_dev_pci_read_byte(PCIDevice *, int)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>cond_false</b>: Condition "pos < 64", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:419:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:417:9: <b>lower_bounds</b>: Checking lower bounds of signed scalar "pos" by "pos < 64".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:424:9: <b>cond_false</b>: Condition "id == 255", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:426:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:427:9: <b>cond_true</b>: Condition "id == cap", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:428:13: <b>return_tainted_data</b>: Returning tainted variable "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>lower_bounds</b>: Casting narrower unsigned "pci_find_cap_offset(pci_dev, 9, pos)" to wider signed type int effectively tests its lower bound.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>var_assign</b>: Assigning: "pos" = "pci_find_cap_offset(PCIDevice *, uint8_t, uint8_t)", which taints "pos".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1496: <b>cond_true</b>: Condition "pos = pci_find_cap_offset(pci_dev, 9, pos)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1501: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1503: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1505: <b>tainted_data</b>: Passing tainted variable "pos" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1233:5: <b>data_index</b>: Passing tainted variable "offset" to a tainted data index sink.</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:394:5: <b>data_index</b>: Using tainted variable "offset" as an index to array "dev->emulate_config_read". <a name='def1055'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1055'>[#def1055]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "ret < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "*__errno_location() == 16", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:978: <b>cond_true</b>: Condition "first", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:980: <b>tainted_data_return</b>: Function "usb_linux_get_num_interfaces(USBHostDevice *)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:535:5: <b>tainted_data_argument</b>: Function "usb_host_read_file(char *, size_t, char const *, char const *)" taints argument "line".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1626:5: <b>cond_true</b>: Condition "f", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:1627:9: <b>tainted_data_argument</b>: Calling function "fgets(char * restrict, int, FILE * restrict)" taints parameter "*line".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:535:5: <b>cond_false</b>: Condition "!usb_host_read_file(line, 1024UL /* sizeof (line) */, "bNumInterfaces", device_name)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:538:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:539:5: <b>vararg_transitive</b>: Call to "sscanf(char const * restrict, char const * restrict, ...)" with tainted argument "line" taints "num_interfaces".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:539:5: <b>cond_false</b>: Condition "sscanf(line, "%d", &num_interfaces) != 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:541:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:542:5: <b>return_tainted_data</b>: Returning tainted variable "num_interfaces".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:980: <b>var_assign</b>: Assigning: "count" = "usb_linux_get_num_interfaces(USBHostDevice *)", which taints "count".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:981: <b>cond_true</b>: Condition "count > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:981: <b>lower_bounds</b>: Checking lower bounds of signed scalar "count" by "count > 0".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/host-linux.c:983: <b>tainted_data</b>: Passing tainted variable "count" to a tainted sink.</span> qemu-kvm-1.2.0/hw/usb/host-linux.c:515:5: <b>a_loop_bound</b>: Using tainted variable "nb_interfaces" as a loop boundary. <a name='def1056'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1056'>[#def1056]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>cond_true</b>: Condition "addr < real_end", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:165: <b>cond_true</b>: Condition "addr < start", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:167: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:164: <b>cond_false</b>: Condition "addr < real_end", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:167: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:169: <b>cond_true</b>: Condition "prot1 == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:173: <b>cond_false</b>: Condition "p == (void *)0xffffffffffffffff", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:174: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:180: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:183: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:183: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:185: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:188: <b>cond_true</b>: Condition "!(prot1 & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:192: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> qemu-kvm-1.2.0/linux-user/mmap.c:192: <b>tainted_data</b>: Passing tainted variable "end - start" to a tainted sink. <a name='def1057'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1057'>[#def1057]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:584: <b>tainted_data</b>: Passing tainted variable "start + len" to a tainted sink.</span> qemu-kvm-1.2.0/exec.c:1076:5: <b>a_loop_bound</b>: Using tainted variable "end" as a loop boundary. <a name='def1058'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1058'>[#def1058]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/elfload.c:1763: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. <a name='def1059'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1059'>[#def1059]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> qemu-kvm-1.2.0/linux-user/elfload.c:1769: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. <a name='def1060'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1060'>[#def1060]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_false</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>else_branch</b>: Reached else branch</span> qemu-kvm-1.2.0/linux-user/elfload.c:1772: <b>tainted_data</b>: Passing tainted variable "eppnt->p_filesz" to a tainted sink. <a name='def1061'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1061'>[#def1061]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_true</b>: Condition "eppnt->p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1713: <b>cond_true</b>: Condition "eppnt->p_flags & 4", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1714: <b>cond_true</b>: Condition "eppnt->p_flags & 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1715: <b>cond_true</b>: Condition "eppnt->p_flags & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1721: <b>tainted_data</b>: Passing tainted variable "eppnt->p_offset - vaddr_po" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:461:12: <b>var_assign_alias</b>: Assigning: "len" = "sb.st_size - offset". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "pread(int, void *, size_t, __off64_t)". <a name='def1062'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1062'>[#def1062]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620: <b>cond_false</b>: Condition "ehdr->e_phoff + i <= 1024", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1624: <b>tainted_data_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "phdr".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1625: <b>cond_false</b>: Condition "retval != i", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1627: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1640: <b>cond_true</b>: Condition "(phdr + i).p_type == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1642: <b>cond_true</b>: Condition "a < loaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1646: <b>cond_true</b>: Condition "a > hiaddr", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1639: <b>cond_false</b>: Condition "i < ehdr->e_phnum", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1653: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1656: <b>cond_true</b>: Condition "ehdr->e_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1665: <b>cond_false</b>: Condition "load_addr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1667: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1668: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1673: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1707: <b>cond_true</b>: Condition "i < ehdr->e_phnum", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1708: <b>var_assign_var</b>: Assigning: "eppnt" = "phdr + i". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1709: <b>cond_false</b>: Condition "eppnt->p_type == 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "eppnt->p_type == 3", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1756: <b>cond_true</b>: Condition "pinterp_name", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1759: <b>cond_false</b>: Condition "*pinterp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1762: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1764: <b>cond_false</b>: Condition "!interp_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1766: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1768: <b>cond_true</b>: Condition "eppnt->p_offset + eppnt->p_filesz <= 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1771: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1777: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/elfload.c:1778: <b>tainted_data</b>: Using tainted variable "eppnt->p_filesz - 1U" as an index to pointer "interp_name". <a name='def1063'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1063'>[#def1063]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1817: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1819: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1821: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "bprm_buf".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1822: <b>cond_false</b>: Condition "retval < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1824: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1825: <b>cond_true</b>: Condition "retval < 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1829: <b>tainted_data</b>: Passing tainted variable "bprm_buf" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1603:25: <b>var_assign_parm</b>: Assigning: "ehdr" = "bprm_buf". "ehdr" is now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1611:5: <b>cond_false</b>: Condition "!elf_check_ident(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1613:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1615:5: <b>cond_false</b>: Condition "!elf_check_ehdr(ehdr)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1617:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1620:5: <b>cond_true</b>: Condition "ehdr->e_phoff + i <= 1024", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1622:5: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1628:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:1629:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "ehdr->e_phnum" to tainted data sink "bswap_phdr(struct elf32_phdr *, int)".</span> qemu-kvm-1.2.0/linux-user/elfload.c:1084:5: <b>a_loop_bound</b>: Using tainted variable "phnum" as a loop boundary. <a name='def1064'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1064'>[#def1064]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:600: <b>cond_false</b>: Condition "reader_status == VREADER_OK", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:608: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:615: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:653: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:654: <b>cond_true</b>: Condition "rv >= 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:594: <b>var_assign_var</b>: Assigning: "dwSendLength" = "mhHeader.length". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:597: <b>tainted_data</b>: Passing tainted variable "dwSendLength" to a tainted sink.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:199:5: <b>cond_false</b>: Condition "card == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:201:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vreader.c:203:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "send_buf_len" to tainted data sink "vcard_apdu_new(unsigned char *, int, vcard_7816_status_t *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:334:5: <b>cond_false</b>: Condition "len < 4", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:337:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/card_7816.c:334:5: <b>lower_bounds</b>: Checking lower bounds of signed scalar "len" by "len < 4".</span> qemu-kvm-1.2.0/libcacard/card_7816.c:341:5: <b>tainted_data_sink_lv_call</b>: Passing tainted variable "len" to tainted data sink "memcpy(void * restrict, void const * restrict, size_t)". <a name='def1065'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1065'>[#def1065]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> qemu-kvm-1.2.0/libcacard/vscclient.c:575: <b>tainted_data</b>: Passing tainted variable "mhHeader.length" to a tainted sink. <a name='def1066'/><b>Error: <span style='background: #C0FF00;'>TAINTED_SCALAR</span> (CWE-20):</b> <a href ='#def1066'>[#def1066]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:452: <b>switch_case</b>: Reached case "99"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:453: <b>cond_false</b>: Condition "cert_count >= 100", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:456: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:458: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_true</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:451: <b>switch</b>: Switch case value "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:459: <b>switch_case</b>: Reached case "101"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:461: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:469: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:450: <b>cond_false</b>: Condition "(c = getopt(argc, argv, "c:e:pd:")) != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:470: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:472: <b>cond_false</b>: Condition "argc - optind != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:475: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:477: <b>cond_true</b>: Condition "cert_count > 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:483: <b>cond_true</b>: Condition "emul_args == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:489: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:491: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_true</b>: Condition "i < cert_count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:495: <b>cond_false</b>: Condition "i < cert_count", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:498: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:502: <b>cond_true</b>: Condition "emul_args", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:506: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:507: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:509: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:512: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:535: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:536: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:540: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:544: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:545: <b>cond_true</b>: Condition "(fds.fds_bits[({...})] & (2L /* (__fd_mask)1 << 1 % (8 * (int)sizeof (__fd_mask)) */)) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:548: <b>cond_false</b>: Condition "!((fds.fds_bits[({...})] & (1L /* (__fd_mask)1 */ << sock % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:550: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:552: <b>tainted_data_argument</b>: Calling function "read(int, void *, size_t)" taints argument "mhHeader".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:553: <b>cond_false</b>: Condition "rv < 12UL /* sizeof (mhHeader) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:561: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:565: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:570: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:571: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:576: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:580: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:581: <b>switch</b>: Switch case value "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:582: <b>switch_case</b>: Reached case "7U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:583: <b>cond_false</b>: Condition "rv < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:588: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:589: <b>cond_true</b>: Condition "verbose", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:591: <b>tainted_data</b>: Passing tainted variable "mhHeader.length" to a tainted sink.</span> qemu-kvm-1.2.0/libcacard/vscclient.c:35:5: <b>a_loop_bound</b>: Using tainted variable "nSize" as a loop boundary. <a name='def1067'/><b>Error: <span style='background: #C0FF00;'>TAINTED_STRING</span> (CWE-20):</b> <a href ='#def1067'>[#def1067]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string_return_content</b>: "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted string content.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_string_return_content</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted string content.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_string_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_string</b>: Returning tainted string "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6))", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_string</b>: Returning tainted string "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(env, n, env->dregs[1], env->dregs[2], env->dregs[3], env->dregs[4], env->dregs[5], env->aregs[0], 0, 0)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string</b>: Passing tainted string "env->dregs[1]" to "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which cannot accept tainted data. <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "8"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5224:10: <b>switch_case</b>: Reached case "8"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>tainted_data_transitive</b>: Call to function "lock_user_string(abi_ulong)" with tainted argument "arg1" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>tainted_data_transitive</b>: Calling function "lock_user(int, abi_ulong, long, int)" with tainted argument "guest_addr" results in tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_false</b>: Condition "!access_ok(type, guest_addr, len)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:421:5: <b>return_tainted_data</b>: Returning tainted variable "(void *)((unsigned long)(target_ulong)guest_addr + guest_base)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_tainted_data</b>: Returning tainted variable "lock_user(0, guest_addr, (long)(len + 1), 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>var_assign_var</b>: Assigning: "p" = "lock_user_string(arg1)". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5225:9: <b>cond_false</b>: Condition "!(p = lock_user_string(arg1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5226:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5227:9: <b>tainted_string_sink_content_lv_call</b>: Passing tainted string "p" to "creat(char const *, mode_t)", which depends on its content.</span> <a name='def1068'/><b>Error: <span style='background: #C0FF00;'>TAINTED_STRING</span> (CWE-20):</b> <a href ='#def1068'>[#def1068]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2624: <b>switch_case</b>: Reached case "4"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2626: <b>cond_true</b>: Condition "ts->sim_syscalls", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2631: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2633: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2635: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string_return_content</b>: "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)" returns tainted string content.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6380:10: <b>switch_case</b>: Reached case "90"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6387:13: <b>cond_false</b>: Condition "!(v = lock_user(0, arg1, 24L /* 6 * sizeof (abi_ulong) */, 1))", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6388:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_string_return_content</b>: Function "target_mmap(abi_ulong, abi_ulong, int, int, int, abi_ulong)" returning tainted string content.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:414:5: <b>cond_false</b>: Condition "offset & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:417:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:420:5: <b>cond_false</b>: Condition "len == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:421:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:427:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:435:5: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "qemu_real_host_page_size < (8192UL /* 1 << 13 */)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:449:5: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:453:8: <b>cond_false</b>: Condition "fstat(fd, &sb) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:454:12: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:457:8: <b>cond_true</b>: Condition "offset + len > sb.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:467:5: <b>cond_false</b>: Condition "!(flags & 0x10)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:489:12: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:490:9: <b>cond_false</b>: Condition "start & 8191U /* ~~((1 << 13) - 1) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:493:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:502:9: <b>cond_false</b>: Condition "(unsigned long)start + len - 1 > 4294967295UL /* (abi_ulong)-1 */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:505:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "!(flags & 0x20)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:509:9: <b>cond_true</b>: Condition "(offset & ~qemu_host_page_mask) != (start & ~qemu_host_page_mask)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_true</b>: Condition "(flags & 0xf) == 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:513:13: <b>cond_false</b>: Condition "prot & 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:517:13: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:521:13: <b>cond_false</b>: Condition "retaddr == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:522:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>tainted_string_argument</b>: Calling function "pread(int, void *, size_t, __off64_t)" taints argument "(unsigned long)(target_ulong)start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:523:13: <b>cond_false</b>: Condition "pread(fd, (void *)((unsigned long)(target_ulong)start + guest_base), len, offset) == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:524:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:525:13: <b>cond_true</b>: Condition "!(prot & 2)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:527:17: <b>cond_false</b>: Condition "ret != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:530:17: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:532:13: <b>goto</b>: Jumping to label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:578:2: <b>label</b>: Reached label "the_end"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/mmap.c:586:5: <b>return_tainted_string</b>: Returning tainted string "start".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>tainted_data_transitive</b>: Call to function "get_errno(abi_long)" with tainted argument "target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6)" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:735:5: <b>cond_false</b>: Condition "ret == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:738:9: <b>return_tainted_data</b>: Returning tainted variable "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6396:13: <b>var_assign</b>: Assigning: "ret" = "get_errno(target_mmap(v1, v2, v3, target_to_host_bitmask(v4, mmap_flags_tbl), v5, v6))", which taints "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:6406:9: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8833:5: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8838:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:8840:5: <b>return_tainted_string</b>: Returning tainted string "ret".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2656: <b>var_assign</b>: Assigning: "env->dregs[0]" = "do_syscall(env, n, env->dregs[1], env->dregs[2], env->dregs[3], env->dregs[4], env->dregs[5], env->aregs[0], 0, 0)", which taints "env->dregs[0]".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2636: <b>switch_case</b>: Reached case "257"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2640: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2666: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2699: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2701: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2621: <b>cond_true</b>: Condition "true", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2623: <b>switch</b>: Switch case value "32"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/main.c:2651: <b>switch_case</b>: Reached case "32"</span> qemu-kvm-1.2.0/linux-user/main.c:2656: <b>tainted_string</b>: Passing tainted string "env->dregs[2]" to "do_syscall(void *, int, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long, abi_long)", which cannot accept tainted data. <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5103:5: <b>cond_true</b>: Condition "do_strace", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5106:5: <b>switch</b>: Switch case value "38"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5582:10: <b>switch_case</b>: Reached case "38"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5586:13: <b>tainted_data_transitive</b>: Call to function "lock_user_string(abi_ulong)" with tainted argument "arg2" returns tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:452:5: <b>cond_false</b>: Condition "len < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:453:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>tainted_data_transitive</b>: Calling function "lock_user(int, abi_ulong, long, int)" with tainted argument "guest_addr" results in tainted data.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:408:5: <b>cond_false</b>: Condition "!access_ok(type, guest_addr, len)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:409:9: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:421:5: <b>return_tainted_data</b>: Returning tainted variable "(void *)((unsigned long)(target_ulong)guest_addr + guest_base)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/qemu.h:454:5: <b>return_tainted_data</b>: Returning tainted variable "lock_user(0, guest_addr, (long)(len + 1), 1)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5586:13: <b>var_assign_var</b>: Assigning: "p2" = "lock_user_string(arg2)". Both are now tainted.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5587:13: <b>cond_false</b>: Condition "!p", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5587:13: <b>cond_false</b>: Condition "!p2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5590:17: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/syscall.c:5590:17: <b>tainted_string_sink_content_lv_call</b>: Passing tainted string "p2" to "rename(char const *, char const *)", which depends on its content.</span> <a name='def1069'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1069'>[#def1069]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:857: <b>cond_true</b>: Condition "ctx->export_flags & 0x20", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:858: <b>fs_check_call</b>: Calling function "lstat(char const *, struct stat *)" to perform check on "rpath(ctx, path, buffer)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:859: <b>cond_false</b>: Condition "err", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:861: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:866: <b>cond_true</b>: Condition "(stbuf.st_mode & 61440) == 16384", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:869: <b>cond_true</b>: Condition "err < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:869: <b>cond_false</b>: Condition "*__errno_location() != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:875: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:882: <b>cond_true</b>: Condition "err < 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:882: <b>cond_false</b>: Condition "*__errno_location() != 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:888: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/9pfs/virtio-9p-local.c:890: <b>toctou</b>: Calling function "remove(char const *)" that uses "rpath(ctx, path, buffer)" after a check function. This can cause a time-of-check, time-of-use race condition. <a name='def1070'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1070'>[#def1070]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:119: <b>cond_true</b>: Condition "dns_addr.s_addr != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:121: <b>cond_false</b>: Condition "curtime - dns_addr_time < 1000", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:124: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:126: <b>fs_check_call</b>: Calling function "stat(char const *, struct stat *)" to perform check on ""/etc/resolv.conf"".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:126: <b>cond_false</b>: Condition "stat("/etc/resolv.conf", &dns_addr_stat) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:127: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_dev == old_stat.st_dev", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_ino == old_stat.st_ino", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_true</b>: Condition "dns_addr_stat.st_size == old_stat.st_size", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:128: <b>cond_false</b>: Condition "dns_addr_stat.st_mtim.tv_sec == old_stat.st_mtim.tv_sec", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:134: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/slirp/slirp.c:137: <b>toctou</b>: Calling function "fopen(char const * restrict, char const * restrict)" that uses ""/etc/resolv.conf"" after a check function. This can cause a time-of-check, time-of-use race condition. <a name='def1071'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1071'>[#def1071]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1873: <b>cond_false</b>: Condition "dev->dev.romfile", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1873: <b>cond_false</b>: Condition "!dev->dev.rom_bar", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1875: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1882: <b>cond_false</b>: Condition "stat(rom_file, &st)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1884: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1886: <b>fs_check_call</b>: Calling function "access(char const *, int)" to perform check on "rom_file".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1886: <b>cond_false</b>: Condition "access(rom_file, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1890: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/kvm/pci-assign.c:1893: <b>toctou</b>: Calling function "fopen(char const * restrict, char const * restrict)" that uses "rom_file" after a check function. This can cause a time-of-check, time-of-use race condition. <a name='def1072'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1072'>[#def1072]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:242: <b>fs_check_call</b>: Calling function "stat(char const *, struct stat *)" to perform check on "path".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:249: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:249: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:255: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_false</b>: Condition "i < 2", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:256: <b>loop_end</b>: Reached end of loop</span> qemu-kvm-1.2.0/oslib-posix.c:258: <b>toctou</b>: Calling function "utimes(char const *, struct timeval const *)" that uses "path" after a check function. This can cause a time-of-check, time-of-use race condition. <a name='def1073'/><b>Error: <span style='background: #C0FF00;'>TOCTOU</span> (CWE-367):</b> <a href ='#def1073'>[#def1073]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "112"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1006: <b>switch_case</b>: Reached case "112"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1007: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1008: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "110"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1009: <b>switch_case</b>: Reached case "110"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1011: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_false</b>: Condition "c == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1004: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1005: <b>switch</b>: Switch case value "102"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1012: <b>switch_case</b>: Reached case "102"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1014: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1029: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop</b>: Jumping back to the beginning of the loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>loop_begin</b>: Jumped back to beginning of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:998: <b>cond_true</b>: Condition "1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1002: <b>cond_true</b>: Condition "c == -1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1003: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1030: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_true</b>: Condition "sock_name == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_false</b>: Condition "sock == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1033: <b>cond_false</b>: Condition "rpath == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1037: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1039: <b>cond_false</b>: Condition "sock_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1043: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1045: <b>cond_false</b>: Condition "sock_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1051: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1053: <b>cond_false</b>: Condition "lstat(rpath, &stbuf) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1057: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1059: <b>cond_false</b>: Condition "!((stbuf.st_mode & 61440) == 16384)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1062: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1064: <b>cond_false</b>: Condition "is_daemon", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1070: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1073: <b>cond_false</b>: Condition "sock_name", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1078: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1083: <b>fs_check_call</b>: Calling function "statfs(char const *, struct statfs *)" to perform check on "rpath".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1084: <b>cond_true</b>: Condition "!retval", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1085: <b>switch</b>: Switch case value "61267L"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1086: <b>switch_case</b>: Reached case "61267L"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1091: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1092: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1096: <b>cond_false</b>: Condition "chdir("/") < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1099: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/fsdev/virtfs-proxy-helper.c:1100: <b>toctou</b>: Calling function "chroot(char const *)" that uses "rpath" after a check function. This can cause a time-of-check, time-of-use race condition. <a name='def1074'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1074'>[#def1074]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:344: <b>var_decl</b>: Declaring variable "cpkt" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:350: <b>cond_false</b>: Condition "len < 8UL /* sizeof (cpkt) */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:353: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:360: <b>cond_false</b>: Condition "cpkt.event == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:374: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:377: <b>cond_false</b>: Condition "!port", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:387: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:388: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:389: <b>cond_false</b>: Condition "!cpkt.value", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:393: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:401: <b>cond_true</b>: Condition "vsc->is_console", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/virtio-serial-bus.c:405: <b>cond_true</b>: Condition "port->name", taking true branch</span> qemu-kvm-1.2.0/hw/virtio-serial-bus.c:412: <b>uninit_use_in_call</b>: Using uninitialized value "cpkt": field "cpkt"."id" is uninitialized when calling "memcpy(void * restrict, void const * restrict, size_t)". <a name='def1075'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1075'>[#def1075]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2753: <b>var_decl</b>: Declaring variable "info" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2764: <b>cond_false</b>: Condition "dumpsize.rlim_cur == 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2765: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2767: <b>cond_false</b>: Condition "core_dump_filename(ts, corefile, 4096UL /* sizeof (corefile) */) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2768: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2770: <b>cond_false</b>: Condition "(fd = open(corefile, 65 /* 1 | 0x40 */, 420 /* ((0x100 | 0x80) | (0x100 >> 3)) | ((0x100 >> 3) >> 3) */)) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2772: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2779: <b>cond_true</b>: Condition "(mm = vma_init()) == NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2780: <b>goto</b>: Jumping to label "out"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2879: <b>label</b>: Reached label "out"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.notes" when calling "free_note_info(struct elf_note_info *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2682:5: <b>read_parm_fld</b>: Reading a parameter field.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.prstatus" when calling "free_note_info(struct elf_note_info *)".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2680:5: <b>read_parm_fld</b>: Reading a parameter field.</span> qemu-kvm-1.2.0/linux-user/elfload.c:2880: <b>uninit_use_in_call</b>: Using uninitialized value "info.psinfo" when calling "free_note_info(struct elf_note_info *)". <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2674:5: <b>cond_false</b>: Condition "!(info->thread_list.tqh_first == NULL)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2678:5: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/elfload.c:2681:5: <b>read_parm_fld</b>: Reading a parameter field.</span> <a name='def1076'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1076'>[#def1076]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:372: <b>var_decl</b>: Declaring variable "act" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:377: <b>cond_false</b>: Condition "core_dump_signal(target_sig)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:381: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:382: <b>cond_false</b>: Condition "core_dumped", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/signal.c:391: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/linux-user/signal.c:401: <b>uninit_use_in_call</b>: Using uninitialized value "act.sa_flags" when calling "sigaction(int, struct sigaction const * restrict, struct sigaction * restrict)". <a name='def1077'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1077'>[#def1077]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1078: <b>var_decl</b>: Declaring variable "p" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1081: <b>cond_false</b>: Condition "!usb_enabled", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1082: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1086: <b>cond_false</b>: Condition "dev", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1087: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1096: <b>cond_true</b>: Condition "!__coverity_strcmp(devname, "bt")", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:1097: <b>cond_true</b>: Condition "devname[2]", taking true branch</span> qemu-kvm-1.2.0/vl.c:1097: <b>uninit_use_in_call</b>: Using uninitialized value "p" when calling "hci_init(char const *)". <span style='color: #808080;'>qemu-kvm-1.2.0/vl.c:640:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1078'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1078'>[#def1078]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1017: <b>var_decl</b>: Declaring variable "qhdb" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1029: <b>cond_true</b>: Condition "is_valid(link)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1029: <b>cond_true</b>: Condition "cnt", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1030: <b>cond_false</b>: Condition "s->frame_bytes >= s->frame_bandwidth", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1035: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1036: <b>cond_true</b>: Condition "is_qh(link)", taking true branch</span> qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:1040: <b>uninit_use_in_call</b>: Using uninitialized element of array "qhdb.addr" when calling "qhdb_insert(QhDb *, uint32_t)". <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:965:5: <b>cond_true</b>: Condition "i < db->count", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/usb/hcd-uhci.c:966:9: <b>read_parm_fld</b>: Reading a parameter field.</span> <a name='def1079'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1079'>[#def1079]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:350: <b>var_decl</b>: Declaring variable "saddr" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:361: <b>cond_false</b>: Condition "is_connected", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:385: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:389: <b>cond_false</b>: Condition "is_connected", taking false branch</span> qemu-kvm-1.2.0/net/socket.c:392: <b>uninit_use</b>: Using uninitialized value "saddr.sin_port". <a name='def1080'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1080'>[#def1080]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:352: <b>var_decl</b>: Declaring variable "saddr_len" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:361: <b>cond_true</b>: Condition "is_connected", taking true branch</span> qemu-kvm-1.2.0/net/socket.c:362: <b>uninit_use_in_call</b>: Using uninitialized value "saddr_len" when calling "getsockname(int, __SOCKADDR_ARG, socklen_t * restrict)". <a name='def1081'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1081'>[#def1081]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:648: <b>var_decl</b>: Declaring variable "raddr" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:650: <b>cond_false</b>: Condition "parse_host_port(&laddr, lhost) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:652: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:654: <b>cond_false</b>: Condition "parse_host_port(&raddr, rhost) < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:656: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:659: <b>cond_false</b>: Condition "fd < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:662: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:666: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:670: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:672: <b>cond_false</b>: Condition "ret < 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:676: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:679: <b>cond_false</b>: Condition "!s", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/net/socket.c:681: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/net/socket.c:683: <b>uninit_use</b>: Using uninitialized value "raddr": field "raddr"."sin_zero" is uninitialized. <a name='def1082'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1082'>[#def1082]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/block/nbd.c:303: <b>var_decl</b>: Declaring variable "request" without initializer.</span> qemu-kvm-1.2.0/block/nbd.c:308: <b>uninit_use_in_call</b>: Using uninitialized value "request.handle" when calling "nbd_send_request(int, struct nbd_request *)". <span style='color: #808080;'>qemu-kvm-1.2.0/nbd.c:485:5: <b>read_parm_fld</b>: Reading a parameter field.</span> <a name='def1083'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1083'>[#def1083]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:216: <b>var_decl</b>: Declaring variable "tv_now" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:240: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> qemu-kvm-1.2.0/oslib-posix.c:247: <b>uninit_use</b>: Using uninitialized value "tv_now.tv_sec". <a name='def1084'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1084'>[#def1084]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:216: <b>var_decl</b>: Declaring variable "tv_now" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "ret != -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:223: <b>cond_false</b>: Condition "*__errno_location() != 38", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:225: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:230: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:232: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:233: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:235: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 0).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:238: <b>cond_false</b>: Condition "(times + 1).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:240: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:241: <b>cond_true</b>: Condition "(times + 0).tv_nsec == 1073741822L /* (1L << 30) - 2L */", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:245: <b>cond_true</b>: Condition "i < 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/oslib-posix.c:246: <b>cond_true</b>: Condition "(times + i).tv_nsec == 1073741823L /* (1L << 30) - 1L */", taking true branch</span> qemu-kvm-1.2.0/oslib-posix.c:248: <b>uninit_use</b>: Using uninitialized value "tv_now.tv_usec". <a name='def1085'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1085'>[#def1085]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/iohandler.c:206: <b>var_decl</b>: Declaring variable "act" without initializer.</span> qemu-kvm-1.2.0/iohandler.c:211: <b>uninit_use_in_call</b>: Using uninitialized value "act.sa_mask": field "act.sa_mask"."__val" is uninitialized when calling "sigaction(int, struct sigaction const * restrict, struct sigaction * restrict)". <a name='def1086'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1086'>[#def1086]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:424: <b>var_decl</b>: Declaring variable "ret" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:426: <b>cond_false</b>: Condition "slirp_instances.tqh_first == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:428: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:436: <b>cond_true</b>: Condition "slirp", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:440: <b>cond_true</b>: Condition "time_fasttimo", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:440: <b>cond_true</b>: Condition "curtime - time_fasttimo >= 2", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:444: <b>cond_true</b>: Condition "do_slowtimo", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:444: <b>cond_true</b>: Condition "curtime - last_slowtimo >= 499", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:453: <b>cond_true</b>: Condition "!select_error", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:457: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_true</b>: Condition "so->so_state & 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:466: <b>continue</b>: Continuing loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:568: <b>loop</b>: Looping back</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:457: <b>cond_true</b>: Condition "so != &slirp->tcb", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_false</b>: Condition "so->so_state & 1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:465: <b>cond_false</b>: Condition "so->s == -1", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:466: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:473: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:473: <b>cond_true</b>: Condition "(xfds->fds_bits[({...})] & (1L /* (__fd_mask)1 */ << so->s % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:474: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:491: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:496: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:496: <b>cond_true</b>: Condition "(writefds->fds_bits[({...})] & (1L /* (__fd_mask)1 */ << so->s % (64 /* 8 * (int)sizeof (__fd_mask) */))) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/slirp/slirp.c:500: <b>cond_true</b>: Condition "so->so_state & 2", taking true branch</span> qemu-kvm-1.2.0/slirp/slirp.c:504: <b>uninit_use_in_call</b>: Using uninitialized value "ret" when calling "send(int, void const *, size_t, int)". <a name='def1087'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1087'>[#def1087]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:64: <b>var_decl</b>: Declaring variable "mhHeader" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/libcacard/vscclient.c:68: <b>cond_true</b>: Condition "verbose > 10", taking true branch</span> qemu-kvm-1.2.0/libcacard/vscclient.c:76: <b>uninit_use_in_call</b>: Using uninitialized value "mhHeader": field "mhHeader"."data" is uninitialized when calling "write(int, void const *, size_t)". <a name='def1088'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1088'>[#def1088]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:66: <b>var_decl</b>: Declaring variable "entry" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:68: <b>cond_true</b>: Condition "kernel_filename", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:68: <b>cond_false</b>: Condition "!qtest_enabled()", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/hw/openrisc_sim.c:88: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/hw/openrisc_sim.c:90: <b>uninit_use</b>: Using uninitialized value "entry". <a name='def1089'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1089'>[#def1089]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "0U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:97: <b>switch_case</b>: Reached case "0U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:98: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_add(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3419:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1090'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1090'>[#def1090]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "4194304U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:114: <b>switch_case</b>: Reached case "4194304U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:116: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_div(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3530:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1091'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1091'>[#def1091]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "5242880U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:119: <b>switch_case</b>: Reached case "5242880U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:121: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_div(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3529:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1092'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1092'>[#def1092]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "1048576U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:101: <b>switch_case</b>: Reached case "1048576U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:103: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_mul(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3468:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1093'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1093'>[#def1093]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "8388608U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:134: <b>switch_case</b>: Reached case "8388608U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:135: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_rem(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3603:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1094'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1094'>[#def1094]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "3178496U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:173: <b>switch_case</b>: Reached case "3178496U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:175: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_round_to_int(float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3196:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1095'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1095'>[#def1095]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "4227072U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:178: <b>switch_case</b>: Reached case "4227072U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:179: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sqrt(float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3906:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1096'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1096'>[#def1096]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "2097152U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:106: <b>switch_case</b>: Reached case "2097152U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:107: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sub(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3442:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1097'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1097'>[#def1097]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "3145728U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:110: <b>switch_case</b>: Reached case "3145728U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:111: <b>uninit_use_in_call</b>: Using uninitialized value "rFm" when calling "float64_sub(float64, float64, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:3441:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1098'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1098'>[#def1098]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFm" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:46: <b>cond_false</b>: Condition "(opcode & 8) != 0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:51: <b>else_branch</b>: Reached else branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:52: <b>switch</b>: Switch case value "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:62: <b>switch_case</b>: Reached case "3"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:69: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:72: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:75: <b>cond_true</b>: Condition "!((opcode & 32768) != 0)", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:78: <b>switch</b>: Switch case value "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:80: <b>switch_case</b>: Reached case "1"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:82: <b>break</b>: Breaking from switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:89: <b>switch_end</b>: Reached end of switch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:94: <b>switch</b>: Switch case value "32768U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:145: <b>switch_case</b>: Reached case "32768U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/double_cpdo.c:146: <b>uninit_use</b>: Using uninitialized value "rFm". <a name='def1099'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1099'>[#def1099]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "0U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:95: <b>switch_case</b>: Reached case "0U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:96: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_add(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4662:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1100'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1100'>[#def1100]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "4194304U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:112: <b>switch_case</b>: Reached case "4194304U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:114: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_div(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4767:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1101'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1101'>[#def1101]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "5242880U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:117: <b>switch_case</b>: Reached case "5242880U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:119: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_div(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4770:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1102'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1102'>[#def1102]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "1048576U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:99: <b>switch_case</b>: Reached case "1048576U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:101: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_mul(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4707:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1103'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1103'>[#def1103]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "8388608U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:132: <b>switch_case</b>: Reached case "8388608U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:133: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_rem(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4847:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1104'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1104'>[#def1104]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "2097152U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:104: <b>switch_case</b>: Reached case "2097152U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:105: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_sub(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4683:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1105'/><b>Error: <span style='background: #C0FF00;'>UNINIT</span> (CWE-457):</b> <a href ='#def1105'>[#def1105]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:40: <b>var_decl</b>: Declaring variable "rFn" without initializer.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:46: <b>cond_true</b>: Condition "(opcode & 8) != 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:49: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:68: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:70: <b>cond_false</b>: Condition "!((opcode & 32768) != 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:89: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:92: <b>switch</b>: Switch case value "3145728U"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:108: <b>switch_case</b>: Reached case "3145728U"</span> qemu-kvm-1.2.0/linux-user/arm/nwfpe/extended_cpdo.c:109: <b>uninit_use_in_call</b>: Using uninitialized value "rFn": field "rFn"."high" is uninitialized when calling "floatx80_sub(floatx80, floatx80, float_status *)". <span style='color: #808080;'>qemu-kvm-1.2.0/fpu/softfloat.c:4684:5: <b>read_parm</b>: Reading a parameter value.</span> <a name='def1106'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1106'>[#def1106]</a> qemu-kvm-1.2.0/hw/usb/hcd-musb.c:573: <b>unreachable</b>: This code cannot be reached: "switch (ttype){ case 0: ...". <a name='def1107'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1107'>[#def1107]</a> qemu-kvm-1.2.0/gdbstub.c:446: <b>unreachable</b>: Since the loop increment is unreachable, the loop body will never execute more than once. <a name='def1108'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1108'>[#def1108]</a> qemu-kvm-1.2.0/hw/sd.c:343: <b>unreachable</b>: This code cannot be reached: "return sd_crc7(buffer, 5UL)...". <a name='def1109'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1109'>[#def1109]</a> qemu-kvm-1.2.0/hw/ide/microdrive.c:212: <b>unreachable</b>: This code cannot be reached: "if (s->cycle)ret = s->io >>...". <a name='def1110'/><b>Error: <span style='background: #C0FF00;'>UNREACHABLE</span> (CWE-561):</b> <a href ='#def1110'>[#def1110]</a> qemu-kvm-1.2.0/hw/ide/microdrive.c:273: <b>unreachable</b>: This code cannot be reached: "if (s->cycle)ide_data_write...". <a name='def1111'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1111'>[#def1111]</a> qemu-kvm-1.2.0/block/qed.c:679: <b>returned_pointer</b>: Pointer "cb.co" returned by "qemu_coroutine_self()" is never used. <a name='def1112'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1112'>[#def1112]</a> qemu-kvm-1.2.0/block/qed.c:1395: <b>returned_pointer</b>: Pointer "cb.co" returned by "qemu_coroutine_self()" is never used. <a name='def1113'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1113'>[#def1113]</a> qemu-kvm-1.2.0/json-parser.c:545: <b>returned_pointer</b>: Pointer "token" returned by "parser_context_pop_token(ctxt)" is never used. <a name='def1114'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1114'>[#def1114]</a> qemu-kvm-1.2.0/linux-user/mmap.c:484: <b>returned_pointer</b>: Pointer "p" returned by "mmap((void *)((unsigned long)(target_ulong)start + guest_base), len, prot, flags | 0x10, fd, host_offset)" is never used. <a name='def1115'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1115'>[#def1115]</a> qemu-kvm-1.2.0/linux-user/mmap.c:754: <b>returned_pointer</b>: Pointer "host_addr" returned by "mremap((void *)((unsigned long)(target_ulong)old_addr + guest_base), new_size, old_size, flags)" is never used. <a name='def1116'/><b>Error: <span style='background: #C0FF00;'>UNUSED_VALUE</span> (CWE-563):</b> <a href ='#def1116'>[#def1116]</a> qemu-kvm-1.2.0/json-parser.c:466: <b>returned_pointer</b>: Pointer "token" returned by "parser_context_pop_token(ctxt)" is never used. <a name='def1117'/><b>Error: <span style='background: #C0FF00;'>USE_AFTER_FREE</span> (CWE-416):</b> <a href ='#def1117'>[#def1117]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:141: <b>cond_false</b>: Condition "envlist == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:141: <b>cond_false</b>: Condition "env == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:142: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:145: <b>cond_false</b>: Condition "(eq_sign = __coverity_strchr(env, 61)) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:146: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:154: <b>alias</b>: Assigning: "entry" = "envlist->el_entries.lh_first". Now both point to the same storage.</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:154: <b>cond_true</b>: Condition "entry != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:156: <b>cond_true</b>: Condition "__coverity_strncmp(entry->ev_var, env, envname_len) == 0", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:157: <b>break</b>: Breaking from loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:158: <b>loop_end</b>: Reached end of loop</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:160: <b>cond_true</b>: Condition "entry != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:161: <b>cond_true</b>: Condition "entry->ev_link.le_next != NULL", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:163: <b>freed_arg</b>: "free(void *)" frees "entry".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:164: <b>if_fallthrough</b>: Falling through to end of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:166: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:168: <b>cond_false</b>: Condition "(entry = malloc(24UL /* sizeof (*entry) */)) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:169: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:170: <b>cond_false</b>: Condition "0", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:170: <b>cond_false</b>: Condition "(entry->ev_var = ((0 && (size_t)(void const *)(env + 1) - (size_t)(void const *)env == 1) ? ((char const *)env[0] == 0) ? (char *)calloc(1UL /* (size_t)1 */, 1UL /* (size_t)1 */) : ({...}) : __strdup(env))) == NULL", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/envlist.c:173: <b>if_end</b>: End of if statement</span> qemu-kvm-1.2.0/envlist.c:174: <b>use_after_free</b>: Using freed pointer "envlist->el_entries.lh_first". <a name='def1118'/><b>Error: <span style='background: #C0FF00;'>USE_AFTER_FREE</span> (CWE-416):</b> <a href ='#def1118'>[#def1118]</a> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:183: <b>cond_false</b>: Condition "!wav->f", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:185: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:190: <b>cond_false</b>: Condition "fseek(wav->f, 4, 0)", taking false branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:194: <b>if_end</b>: End of if statement</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:195: <b>cond_true</b>: Condition "fwrite(rlen, 4, 1, wav->f) != 1", taking true branch</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:198: <b>goto</b>: Jumping to label "doclose"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:211: <b>label</b>: Reached label "doclose"</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:212: <b>freed_arg</b>: "fclose(FILE *)" frees "wav->f".</span> <span style='color: #808080;'>qemu-kvm-1.2.0/audio/wavaudio.c:212: <b>cond_true</b>: Condition "fclose(wav->f)", taking true branch</span> qemu-kvm-1.2.0/audio/wavaudio.c:213: <b>pass_freed_arg</b>: Passing freed pointer "wav->f" as an argument to function "dolog(char const *, ...)". </pre> <h2>Scan Properties</h2> <table style='font-family: monospace;'> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>analyzer</td><td>coverity</td></tr> <tr><td style='padding-right: 8px;'>analyzer-args</td><td>--wait-for-license --security --concurrency</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>analyzer-version</td><td>Coverity Static Analysis for C/C++ version 6.5.0 on Linux 2.6.32-279.el6.x86_64 x86_64\nInternal version numbers: 5cf350e73a3d7603cb5520c80316bfaded6febde p-carmel-push-12518.257</td></tr> <tr><td style='padding-right: 8px;'>compilation-unit-count</td><td>2633</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>compilation-unit-ratio</td><td>99</td></tr> <tr><td style='padding-right: 8px;'>host</td><td>cov01.lab.eng.brq.redhat.com</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>lines-processed</td><td>761013</td></tr> <tr><td style='padding-right: 8px;'>mock-config</td><td>fedora-rawhide-xscan</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>project-name</td><td>qemu-1.2.0-25.fc19</td></tr> <tr><td style='padding-right: 8px;'>time-created</td><td>2012-12-07 08:44:41</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>time-elapsed-analysis</td><td>00:24:49</td></tr> <tr><td style='padding-right: 8px;'>time-finished</td><td>2012-12-07 09:41:35</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>tool</td><td>cov-mockbuild</td></tr> <tr><td style='padding-right: 8px;'>tool-args</td><td>-i fedora-rawhide-xscan qemu-1.2.0-25.fc19.src.rpm --security --concurrency</td></tr> <tr style='background-color: #EEE;'><td style='padding-right: 8px;'>tool-version</td><td>cov-mockbuild-0.20121127_91fc7f1-1.el6.noarch csdiff-0.20121113_49dc2ca-1.el6.x86_64</td></tr> </table> </body> </html>
View Attachment As Raw
Actions:
View
Attachments on
bug 887927
: 665081