[PATCH] scripts: bloat-o-meter: avoid shell for nm invocation

From: iamzayn19

Date: Sun Sep 27 2026 - 01:34:59 EST


bloat-o-meter builds the nm command with string formatting and then
executes it through the shell. Object file paths containing spaces are
split before nm sees them, so the comparison silently reports empty
results for those files.

Invoke nm with subprocess argv instead. This preserves paths as single
arguments and avoids shell interpretation of filenames and tool prefixes.

Assisted-by: LLM
Signed-off-by: iamzayn19 <iamzayn19@xxxxxxxxx>
---
scripts/bloat-o-meter | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/scripts/bloat-o-meter b/scripts/bloat-o-meter
index 5868a8b..72edbb7 100755
--- a/scripts/bloat-o-meter
+++ b/scripts/bloat-o-meter
@@ -7,7 +7,7 @@
# This software may be used and distributed according to the terms
# of the GNU General Public License, incorporated herein by reference.

-import sys, os, re, argparse
+import argparse, re, subprocess
from signal import signal, SIGPIPE, SIG_DFL

signal(SIGPIPE, SIG_DFL)
@@ -31,8 +31,11 @@ def getsizes(file, format):
if args.prefix:
nm = "{}nm".format(args.prefix)

- with os.popen("{} --size-sort {}".format(nm, file)) as f:
- for line in f:
+ with subprocess.Popen([nm, "--size-sort", file], stdout=subprocess.PIPE,
+ text=True) as f:
+ if f.stdout is None:
+ return sym
+ for line in f.stdout:
if line.startswith("\n") or ":" in line:
continue
size, type, name = line.split()
@@ -49,6 +52,7 @@ def getsizes(file, format):
# statics and some other optimizations adds random .NUMBER
name = re_NUMBER.sub('', name)
sym[name] = sym.get(name, 0) + int(size, 16)
+ f.wait()
return sym

def calc(oldfile, newfile, format):
--
2.44.0