[PATCH v2] scripts: bloat-o-meter: avoid shell parsing file names
From: iamzayn19
Date: Tue Oct 06 2026 - 18:04:28 EST
bloat-o-meter receives file names directly from command-line arguments,
but passes them to nm by interpolating them into a shell command
string.
Use subprocess with an argv list instead. This preserves the argument
boundary for the input file name and avoids shell interpretation of the
file name and tool invocation.
This is a robustness cleanup for direct bloat-o-meter invocations rather
than support for spaces in normal kbuild paths.
Signed-off-by: iamzayn19 <iamzayn19@xxxxxxxxx>
---
scripts/bloat-o-meter | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/scripts/bloat-o-meter b/scripts/bloat-o-meter
index 5868a8b..72edbb7 100755
--- a/scripts/bloat-o-meter
+++ b/scripts/bloat-o-meter
@@ -7,7 +7,7 @@
# This software may be used and distributed according to the terms
# of the GNU General Public License, incorporated herein by reference.
-import sys, os, re, argparse
+import argparse, re, subprocess
from signal import signal, SIGPIPE, SIG_DFL
signal(SIGPIPE, SIG_DFL)
@@ -31,8 +31,11 @@ def getsizes(file, format):
if args.prefix:
nm = "{}nm".format(args.prefix)
- with os.popen("{} --size-sort {}".format(nm, file)) as f:
- for line in f:
+ with subprocess.Popen([nm, "--size-sort", file], stdout=subprocess.PIPE,
+ text=True) as f:
+ if f.stdout is None:
+ return sym
+ for line in f.stdout:
if line.startswith("\n") or ":" in line:
continue
size, type, name = line.split()
@@ -49,6 +52,7 @@ def getsizes(file, format):
# statics and some other optimizations adds random .NUMBER
name = re_NUMBER.sub('', name)
sym[name] = sym.get(name, 0) + int(size, 16)
+ f.wait()
return sym
def calc(oldfile, newfile, format):
--
2.44.0