Re: [PATCH] scripts: bloat-o-meter: avoid shell for nm invocation

From: David Laight

Date: Sun Sep 27 2026 - 03:13:32 EST


On Sun, 27 Sep 2026 10:34:41 +0500
iamzayn19 <iamzayn19@xxxxxxxxx> wrote:

> bloat-o-meter builds the nm command with string formatting and then
> executes it through the shell. Object file paths containing spaces are
> split before nm sees them, so the comparison silently reports empty
> results for those files.

Where are pathnames with spaces coming from?
Make doesn't support them.
Even some windows build environments don't support them.

David

>
> Invoke nm with subprocess argv instead. This preserves paths as single
> arguments and avoids shell interpretation of filenames and tool prefixes.
>
> Assisted-by: LLM
> Signed-off-by: iamzayn19 <iamzayn19@xxxxxxxxx>
> ---
> scripts/bloat-o-meter | 10 +++++++---
> 1 file changed, 7 insertions(+), 3 deletions(-)
>
> diff --git a/scripts/bloat-o-meter b/scripts/bloat-o-meter
> index 5868a8b..72edbb7 100755
> --- a/scripts/bloat-o-meter
> +++ b/scripts/bloat-o-meter
> @@ -7,7 +7,7 @@
> # This software may be used and distributed according to the terms
> # of the GNU General Public License, incorporated herein by reference.
>
> -import sys, os, re, argparse
> +import argparse, re, subprocess
> from signal import signal, SIGPIPE, SIG_DFL
>
> signal(SIGPIPE, SIG_DFL)
> @@ -31,8 +31,11 @@ def getsizes(file, format):
> if args.prefix:
> nm = "{}nm".format(args.prefix)
>
> - with os.popen("{} --size-sort {}".format(nm, file)) as f:
> - for line in f:
> + with subprocess.Popen([nm, "--size-sort", file], stdout=subprocess.PIPE,
> + text=True) as f:
> + if f.stdout is None:
> + return sym
> + for line in f.stdout:
> if line.startswith("\n") or ":" in line:
> continue
> size, type, name = line.split()
> @@ -49,6 +52,7 @@ def getsizes(file, format):
> # statics and some other optimizations adds random .NUMBER
> name = re_NUMBER.sub('', name)
> sym[name] = sym.get(name, 0) + int(size, 16)
> + f.wait()
> return sym
>
> def calc(oldfile, newfile, format):