[PATCH v1 5/5] perf thread: Free the comm read from procfs

From: Ian Rogers

Date: Fri Sep 18 2026 - 02:35:40 EST


procfs__read_str() allocates the buffer it hands back and
thread__set_comm() only stores an interned copy of the string, so the
caller owns the buffer. thread__set_comm_from_proc() freed it when the
read came back empty but not once it had been used, leaking it on
every successful call.

Free it on both paths. The empty read still returns -1, err being
untouched in that case.

Found with leak sanitizer while running 'perf trace':

Direct leak of 7 byte(s) in 1 object(s) allocated from:
#1 io__getdelim fs/../io.h:179
#2 filename__read_str fs/fs.c:365
#3 procfs__read_str fs/fs.c:402
#4 thread__set_comm_from_proc util/thread.c:297
#5 syscall_arg__scnprintf_pid trace/beauty/pid.c:15

Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/util/thread.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/tools/perf/util/thread.c b/tools/perf/util/thread.c
index f0d3773d87db..fcf7c78ab767 100644
--- a/tools/perf/util/thread.c
+++ b/tools/perf/util/thread.c
@@ -296,12 +296,12 @@ int thread__set_comm_from_proc(struct thread *thread)
thread__pid(thread), thread__tid(thread)) >= (int)sizeof(path)) &&
procfs__read_str(path, &comm, &sz) == 0) {
/* sz==0: read got nothing, e.g. race during exit teardown */
- if (sz == 0) {
- free(comm);
- return -1;
+ if (sz > 0) {
+ comm[sz - 1] = '\0';
+ err = thread__set_comm(thread, comm, 0);
}
- comm[sz - 1] = '\0';
- err = thread__set_comm(thread, comm, 0);
+ /* thread__set_comm() copies the string, so release the buffer. */
+ free(comm);
}

return err;
--
2.55.0.1082.g2b9226bbc0-goog