From: Arnaldo Carvalho de Melo <acme@kernel.org>
To: Alan Maguire <alan.maguire@oracle.com>
Cc: Jiri Olsa <jolsa@kernel.org>,
Clark Williams <williams@redhat.com>,
dwarves@vger.kernel.org, bpf@vger.kernel.org,
Andrii Nakryiko <andrii@kernel.org>,
Yonghong Song <yonghong.song@linux.dev>,
Arnaldo Carvalho de Melo <acme@redhat.com>
Subject: [PATCH 05/31] pahole: Fix instance memory leak on early returns in prototype__stdio_fprintf_value
Date: Wed, 29 Jul 2026 16:07:05 -0300 [thread overview]
Message-ID: <20260729190733.72876-6-acme@kernel.org> (raw)
In-Reply-To: <20260729190733.72876-1-acme@kernel.org>
From: Arnaldo Carvalho de Melo <acme@redhat.com>
prototype__stdio_fprintf_value() allocates an instance buffer via
malloc() but has 14 early return statements between the allocation
and the free(instance) at the out: label. None of these early returns
free instance, leaking memory on every error path during --prettify
binary record processing.
Change all bare returns after the successful malloc to 'goto out',
setting printed to the error value before jumping. The out: label
already does free(instance) and return printed.
The return -ENOMEM when instance == NULL (malloc failure) is kept
as-is since there is nothing to free.
Fixes: fdfc64ec44f4ad53 ("pahole: Introduce --range")
Assisted-by: Claude:claude-sonnet-4-5
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
---
pahole.c | 45 ++++++++++++++++++++++++++++-----------------
1 file changed, 28 insertions(+), 17 deletions(-)
diff --git a/pahole.c b/pahole.c
index 390d5f2dd20e4dfd..0096dfa34e5047c8 100644
--- a/pahole.c
+++ b/pahole.c
@@ -2584,9 +2584,9 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
return -ENOMEM;
if (type__instance_read_once(header, input) < 0) {
- int err = --errno;
+ printed = --errno;
fprintf(stderr, "pahole: --header (%s) type couldn't be read\n", conf.header_type);
- return err;
+ goto out;
}
if (conf.range || prototype->range) {
@@ -2598,14 +2598,16 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
fprintf(stderr, "pahole: --header_type=%s not found\n", conf.header_type);
else
fprintf(stderr, "pahole: range (%s) requires --header\n", range);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
char *member_name = NULL;
if (asprintf(&member_name, "%s.%s", range, "offset") == -1) {
fprintf(stderr, "pahole: not enough memory for range=%s\n", range);
- return -ENOMEM;
+ printed = -ENOMEM;
+ goto out;
}
int64_t value = type_instance__int_value(header, member_name);
@@ -2614,7 +2616,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
fprintf(stderr, "pahole: couldn't read the '%s' member of '%s' for evaluating range=%s\n",
member_name, conf.header_type, range);
free(member_name);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
seek_bytes = value;
@@ -2628,7 +2631,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (seek_bytes < total_read_bytes) {
fprintf(stderr, "pahole: can't go back in input, already read %" PRIu64 " bytes, can't go to position %#" PRIx64 "\n",
total_read_bytes, seek_bytes);
- return -ENOMEM;
+ printed = -ENOMEM;
+ goto out;
}
if (global_verbose) {
@@ -2640,7 +2644,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (asprintf(&member_name, "%s.%s", range, "size") == -1) {
fprintf(stderr, "pahole: not enough memory for range=%s\n", range);
- return -ENOMEM;
+ printed = -ENOMEM;
+ goto out;
}
value = type_instance__int_value(header, member_name);
@@ -2649,7 +2654,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
fprintf(stderr, "pahole: couldn't read the '%s' member of '%s' for evaluating range=%s\n",
member_name, conf.header_type, range);
free(member_name);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
size_bytes = value;
@@ -2661,9 +2667,9 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
free(member_name);
if (pipe_seek(input, seek_bytes) < 0) {
- int err = --errno;
+ printed = --errno;
fprintf(stderr, "Couldn't --seek_bytes %s (%" PRIu64 "\n", conf.seek_bytes, seek_bytes);
- return err;
+ goto out;
}
goto do_read;
@@ -2676,7 +2682,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (!header) {
fprintf(stderr, "pahole: --seek_bytes (%s) makes reference to --header but it wasn't specified\n",
conf.seek_bytes);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
const char *member_name = conf.seek_bytes + sizeof("$header.") - 1;
@@ -2684,7 +2691,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (value < 0) {
fprintf(stderr, "pahole: couldn't read the '%s' member of '%s' for evaluating --seek_bytes=%s\n",
member_name, conf.header_type, conf.seek_bytes);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
seek_bytes = value;
@@ -2696,7 +2704,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (seek_bytes < header->type->size) {
fprintf(stderr, "pahole: seek bytes evaluated from --seek_bytes=%s is less than the header type size\n",
conf.seek_bytes);
- return -EINVAL;
+ printed = -EINVAL;
+ goto out;
}
} else {
seek_bytes = strtol(conf.seek_bytes, NULL, 0);
@@ -2709,9 +2718,9 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
}
if (pipe_seek(input, seek_bytes) < 0) {
- int err = --errno;
+ printed = --errno;
fprintf(stderr, "Couldn't --seek_bytes %s (%" PRIu64 "\n", conf.seek_bytes, seek_bytes);
- return err;
+ goto out;
}
}
@@ -2720,7 +2729,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (!header) {
fprintf(stderr, "pahole: --size_bytes (%s) makes reference to --header but it wasn't specified\n",
conf.size_bytes);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
const char *member_name = conf.size_bytes + sizeof("$header.") - 1;
@@ -2728,7 +2738,8 @@ static int prototype__stdio_fprintf_value(struct prototype *prototype, struct ty
if (value < 0) {
fprintf(stderr, "pahole: couldn't read the '%s' member of '%s' for evaluating --size_bytes=%s\n",
member_name, conf.header_type, conf.size_bytes);
- return -ESRCH;
+ printed = -ESRCH;
+ goto out;
}
size_bytes = value;
--
2.55.0
next prev parent reply other threads:[~2026-07-29 19:07 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 19:07 [PATCHES 00/31] pahole: Bug fixes and small improvements Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 01/31] cmake: Update minimum required version from 3.5 to 3.10 Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 02/31] Fix -Wsign-compare warnings across the codebase Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 03/31] btf_encoder: Fix interior pointer free and missing NULL check Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 04/31] dwarves: Fix missing list head initialization in type__clone_members Arnaldo Carvalho de Melo
2026-07-29 19:07 ` Arnaldo Carvalho de Melo [this message]
2026-07-29 19:07 ` [PATCH 06/31] ctf_loader, libctf: Fix error path resource leaks Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 07/31] dwarves: Don't search for holes before member byte sizes are cached Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 08/31] dwarf_loader: Allocate type_dcu via dwarf_cu__new to fix dangling stack pointer Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 09/31] dwarf_loader: Fix annotation failure leaks in variable and typedef creation Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 10/31] btf_encoder: Use btf_encoder__tag_type() for all type ID computations Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 11/31] pahole: Fix --errno typo that decrements instead of negating Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 12/31] dwarves: Fix heap buffer overflow in languages__parse realloc Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 13/31] btf_encoder: Fix early cleanup crashes in btf_encoder__new/delete Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 14/31] btf_encoder, libctf: Add elf_strptr NULL checks and fix kfunc bounds Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 15/31] dwarf_loader: Fix --fixup_silly_bitfields condition check Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 16/31] dwarf_loader: Skip libdw__lock when elfutils is built thread-safe Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 17/31] dwarf_loader: Fix data race in tag__init() decl_file string cache Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 18/31] pahole: Fix parse_btf_features("all") being a silent no-op Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 19/31] dwarves: Fix variable shadowing in __cus__find_struct_by_name() Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 20/31] dutil: Add exec_objcopy() shell-injection-safe helper Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 21/31] btf_encoder: Fall back to objcopy when llvm-objcopy is not available Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 22/31] dwarf_loader, btf_loader: Replace stale FIXME/XXX comments with explanations Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 23/31] pahole: Skip inline expansions during BTF encoding Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 24/31] pahole: Use fseek for seekable files in --prettify and --seek_bytes Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 25/31] pahole: Guard pipe_seek() against negative offsets Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 26/31] gobuffer: Remove 5 dead functions found via coverage analysis Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 27/31] dwarves: Remove 6 " Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 28/31] pfunct, dwarves_fprintf: Mark file-local functions as static Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 29/31] btf_encoder: Fix multi-dimensional array encoding Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 30/31] btf_loader: Fix multi-dimensional array loading Arnaldo Carvalho de Melo
2026-07-29 19:07 ` [PATCH 31/31] btfdiff: Remove --flat_arrays now that pahole encodes multi dim arrays in BTF Arnaldo Carvalho de Melo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729190733.72876-6-acme@kernel.org \
--to=acme@kernel.org \
--cc=acme@redhat.com \
--cc=alan.maguire@oracle.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=dwarves@vger.kernel.org \
--cc=jolsa@kernel.org \
--cc=williams@redhat.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox