Re: [PATCH v3 01/21] perf capstone: Fix kernel map reference count leak

From: Namhyung Kim

Date: Thu Jul 09 2026 - 01:57:19 EST


On Wed, Jul 01, 2026 at 03:53:35AM +0000, Tengda Wu wrote:
> In print_capstone_detail(), maps__find() is used to locate the kernel
> map. This function increments the reference count of the found map
> object. However, the current implementation fails to call map__put()
> after the map is no longer needed, leading to a reference count leak.
>
> Fix this by adding a map__put(map) call to properly release the
> reference after use.
>
> Fixes: 92dfc59463d5 ("perf annotate: Add symbol name when using capstone")
> Signed-off-by: Tengda Wu <wutengda@xxxxxxxxxxxxxxx>

I'll pick this up separately.

Thanks,
Namhyung

> ---
> tools/perf/util/capstone.c | 13 +++++++++----
> 1 file changed, 9 insertions(+), 4 deletions(-)
>
> diff --git a/tools/perf/util/capstone.c b/tools/perf/util/capstone.c
> index 5ad537fea436..9bba78ee0c5a 100644
> --- a/tools/perf/util/capstone.c
> +++ b/tools/perf/util/capstone.c
> @@ -302,6 +302,7 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
> for (i = 0; i < insn->detail->x86.op_count; i++) {
> struct cs_x86_op *op = &insn->detail->x86.operands[i];
> u64 orig_addr;
> + struct map *found_map = NULL;
>
> if (op->type != X86_OP_MEM)
> continue;
> @@ -317,19 +318,22 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
> if (dso__kernel(map__dso(map))) {
> /*
> * The kernel maps can be split into sections, let's
> - * find the map first and the search the symbol.
> + * find the map first and then search the symbol.
> */
> - map = maps__find(map__kmaps(map), addr);
> - if (map == NULL)
> + found_map = maps__find(map__kmaps(map), addr);
> + if (found_map == NULL)
> continue;
> + map = found_map;
> }
>
> /* convert it to map-relative address for search */
> addr = map__map_ip(map, addr);
>
> sym = map__find_symbol(map, addr);
> - if (sym == NULL)
> + if (sym == NULL) {
> + map__put(found_map);
> continue;
> + }
>
> if (addr == sym->start) {
> scnprintf(buf, len, "\t# %"PRIx64" <%s>",
> @@ -338,6 +342,7 @@ static void print_capstone_detail(struct cs_insn *insn, char *buf, size_t len,
> scnprintf(buf, len, "\t# %"PRIx64" <%s+%#"PRIx64">",
> orig_addr, sym->name, addr - sym->start);
> }
> + map__put(found_map);
> break;
> }
> }
> --
> 2.34.1
>