> diff --git a/tools/testing/selftests/bpf/jit_disasm_helpers.c 
> b/tools/testing/selftests/bpf/jit_disasm_helpers.c
> index 364c557c5115..4c6bcbe08491 100644
> --- a/tools/testing/selftests/bpf/jit_disasm_helpers.c
> +++ b/tools/testing/selftests/bpf/jit_disasm_helpers.c
> @@ -170,9 +170,11 @@ int get_jited_program_text(int fd, char *text, size_t 
> text_sz)
>       struct bpf_prog_info info = {};
>       __u32 info_len = sizeof(info);
>       __u32 jited_funcs, len, pc;
> +     __u32 trunc_len = 0;
>       __u32 *func_lens = NULL;
>       FILE *text_out = NULL;
>       uint8_t *image = NULL;
> +     char *triple = NULL;
>       int i, err = 0;
>
>       if (!llvm_initialized) {

[ ... ]

> @@ -216,9 +218,18 @@ int get_jited_program_text(int fd, char *text, size_t 
> text_sz)
>       if (!ASSERT_OK(err, "bpf_prog_get_info_by_fd #2"))
>               goto out;
>
> +     /*
> +      * last 8 bytes contains dummy_trampoline address in JIT
> +      * output for 64-bit and 32-bit powerpc, which can't
> +      * disassemble a to valid instruction.
> +      */
> +     triple = LLVMGetDefaultTargetTriple();
> +     if (strstr(triple, "powerpc"))
> +             trunc_len = 8;
> +

Does this code leak the triple string? Looking at the LLVM C API,
LLVMGetDefaultTargetTriple() returns a string that must be freed with
LLVMDisposeMessage(). The sibling function disasm_one_func() in this
same file shows the correct pattern:

    if (triple)
        LLVMDisposeMessage(triple);

The cleanup section at the 'out:' label properly frees text_out, image,
and func_lens, but triple isn't included. While this is test code and
the leak is small, it violates the established cleanup pattern in the
file and can accumulate across test runs.

>       for (pc = 0, i = 0; i < jited_funcs; ++i) {
>               fprintf(text_out, "func #%d:\n", i);
> -             disasm_one_func(text_out, image + pc, func_lens[i]);
> +             disasm_one_func(text_out, image + pc, func_lens[i] - trunc_len);
>               fprintf(text_out, "\n");
>               pc += func_lens[i];
>       }


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/25998434343

Reply via email to