[PATCH 2/5] perf symbol: Don't return an unterminated Rust demangle buffer
From: Michal Pluta
Date: Sun Sep 27 2026 - 21:03:11 EST
When dso__demangle_sym() runs out of retries or fails to grow the
output buffer for a Rust v0 symbol, it returns the buffer and callers
blindly use it as the demangled symbol name. However,
rust_demangle_display_demangle() doesn't NUL terminate its output when
it reports OverflowOverflow, so the buffer isn't a string.
Free the buffer and return NULL in both cases. Callers already fall back
to the mangled name when no demangled name is returned.
Fixes: e20848c317b5 ("perf symbol-elf: Integrate rust-v0 demangling")
Assisted-by: LLM
Signed-off-by: Michal Pluta <michalpl2003@xxxxxxxxx>
---
tools/perf/util/symbol.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/tools/perf/util/symbol.c b/tools/perf/util/symbol.c
index 163652f071c6..3cb42805a82f 100644
--- a/tools/perf/util/symbol.c
+++ b/tools/perf/util/symbol.c
@@ -2762,17 +2762,16 @@ char *dso__demangle_sym(struct dso *dso, int kmodule, const char *elf_name)
buf_len < 1024 * 1024; buf_len += 32) {
char *tmp = realloc(demangled, buf_len);
- if (!tmp) {
- /* Failure to grow output buffer, return what is there. */
- return demangled;
- }
+ if (!tmp)
+ break;
demangled = tmp;
if (rust_demangle_display_demangle(&rust_demangle, demangled, buf_len,
/*alternate=*/true) == OverflowOk)
return demangled;
}
- /* Buffer exceeded sensible bounds, return what is there. */
- return demangled;
+ /* Failure to grow output buffer or buffer exceeded sensible bounds. */
+ free(demangled);
+ return NULL;
}
demangled = cxx_demangle_sym(elf_name, verbose > 0, verbose > 0);
--
2.43.0