[PATCH v3 01/21] perf capstone: Fix kernel map reference count leak
From: Tengda Wu
Date: Wed Jul 01 2026 - 00:01:57 EST
In print_capstone_detail(), maps__find() is used to locate the kernel
map. This function increments the reference count of the found map
object. However, the current implementation fails to call map__put()
after the map is no longer needed, leading to a reference count leak.
Fix this by adding a map__put(map) call to properly release the
reference after use.
Fixes: 92dfc59463d5 ("perf annotate: Add symbol name when using capstone")
Signed-off-by: Tengda Wu <wutengda@xxxxxxxxxxxxxxx>
---
tools/perf/util/capstone.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/tools/perf/util/capstone.c b/tools/perf/util/capstone.c
index 5ad537fea436..9bba78ee0c5a 100644
--- a/tools/perf/util/capstone.c
+++ b/tools/perf/util/capstone.c
@@ -302,6 +302,7 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
for (i = 0; i < insn->detail->x86.op_count; i++) {
struct cs_x86_op *op = &insn->detail->x86.operands[i];
u64 orig_addr;
+ struct map *found_map = NULL;
if (op->type != X86_OP_MEM)
continue;
@@ -317,19 +318,22 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
if (dso__kernel(map__dso(map))) {
/*
* The kernel maps can be split into sections, let's
- * find the map first and the search the symbol.
+ * find the map first and then search the symbol.
*/
- map = maps__find(map__kmaps(map), addr);
- if (map == NULL)
+ found_map = maps__find(map__kmaps(map), addr);
+ if (found_map == NULL)
continue;
+ map = found_map;
}
/* convert it to map-relative address for search */
addr = map__map_ip(map, addr);
sym = map__find_symbol(map, addr);
- if (sym == NULL)
+ if (sym == NULL) {
+ map__put(found_map);
continue;
+ }
if (addr == sym->start) {
scnprintf(buf, len, "\t# %"PRIx64" <%s>",
@@ -338,6 +342,7 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
scnprintf(buf, len, "\t# %"PRIx64" <%s+%#"PRIx64">",
orig_addr, sym->name, addr - sym->start);
}
+ map__put(found_map);
break;
}
}
--
2.34.1