From: Ian Rogers <irogers@google.com>
To: Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>,
Ingo Molnar <mingo@redhat.com>, Jiri Olsa <jolsa@kernel.org>,
Adrian Hunter <adrian.hunter@intel.com>,
James Clark <james.clark@linaro.org>,
linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org,
Ian Rogers <irogers@google.com>
Subject: [PATCH v1 0/5] perf trace: Tracepoint format error handling and leak fixes
Date: Thu, 17 Sep 2026 23:32:44 -0700 [thread overview]
Message-ID: <20260918063249.2172589-1-irogers@google.com> (raw)
Running 'perf trace' under address sanitizer turned up a handful of
problems around the global tracepoint format cache.
trace_event__tp_format() encoded failures with ERR_PTR(), but
trace_event__tp_format_id() returned a plain NULL when the lookup missed
and tp_format() discarded the return value of tep_parse_format(), so two
of the three failure modes were indistinguishable from success to a
caller using IS_ERR(). syscall__read_info() then dereferenced the NULL.
Patch 1 drops the error pointers and reports failures as NULL with errno
set, which is what the callers were already testing for.
Patch 2 stops re-reading and re-parsing a format file that has already
been parsed. Each parse adds another tep_event to the handle and
libtraceevent can only free the whole handle, so a repeated lookup left
a duplicate behind for the rest of the session.
Patch 3 finally does what the TODO above the global has asked for since
the code was added, and frees the handle once the command is done.
That in turn exposed two leaks that had been hidden because the handle
kept them reachable: patch 4 frees the machine created by
machine__new_host(), which was released with machine__exit() rather than
machine__delete() and so leaked the allocation itself, and patch 5 frees
the buffer procfs__read_str() hands to thread__set_comm_from_proc(),
which is only freed when the read comes back empty.
With these, and with an unrelated libtraceevent fix I will send
separately to linux-trace-devel, 'perf trace' exits with no leaks
reported.
Tested on x86_64. Every patch builds individually, and the series also
builds with NO_LIBTRACEEVENT=1.
Ian Rogers (5):
perf trace-event: Report tracepoint format errors with NULL and errno
perf trace-event: Reuse an already parsed tracepoint format
perf trace-event: Free the global trace_event when a command ends
perf trace: Free the host machine allocation
perf thread: Free the comm read from procfs
tools/perf/builtin-kmem.c | 3 +-
tools/perf/builtin-sched.c | 5 +-
tools/perf/builtin-trace.c | 12 ++---
tools/perf/perf.c | 6 +++
tools/perf/util/evsel.c | 5 +-
tools/perf/util/thread.c | 10 ++--
tools/perf/util/trace-event.c | 90 +++++++++++++++++++++++++++--------
tools/perf/util/trace-event.h | 1 +
8 files changed, 91 insertions(+), 41 deletions(-)
--
2.55.0.1082.g2b9226bbc0-goog
next reply other threads:[~2026-09-18 6:32 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 6:32 Ian Rogers [this message]
2026-09-18 6:32 ` [PATCH v1 1/5] perf trace-event: Report tracepoint format errors with NULL and errno Ian Rogers
2026-09-18 6:32 ` [PATCH v1 2/5] perf trace-event: Reuse an already parsed tracepoint format Ian Rogers
2026-09-18 6:32 ` [PATCH v1 3/5] perf trace-event: Free the global trace_event when a command ends Ian Rogers
2026-09-18 6:32 ` [PATCH v1 4/5] perf trace: Free the host machine allocation Ian Rogers
2026-09-18 6:32 ` [PATCH v1 5/5] perf thread: Free the comm read from procfs Ian Rogers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918063249.2172589-1-irogers@google.com \
--to=irogers@google.com \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=namhyung@kernel.org \
--cc=peterz@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®