{"record":{"id":"d609fe8c482ee737","repo":"influxdata/influxdb","slug":"tempfile-path-was-not-valid-c-string-non-utf8-or-interior","errorCode":null,"errorMessage":"tempfile path was not valid C string (non-utf8 or interior NUL)","messagePattern":"tempfile path was not valid C string \\(non-utf8 or interior NUL\\)","errorType":"error_code","errorClass":"HeapDumpError::BadTempPath","httpStatus":null,"severity":"error","filePath":"core/jemalloc_stats/src/lib.rs","lineNumber":92,"sourceCode":"/// `tikv-jemalloc-sys` prefixes the `MALLOC_CONF` env name on the platforms\n/// in its `NO_UNPREFIXED_MALLOC_TARGETS` list, so the right name to suggest\n/// in a user-facing message differs by build target.\npub const MALLOC_CONF_ENV: &str = if cfg!(any(\n    target_os = \"macos\",\n    target_os = \"ios\",\n    target_os = \"android\",\n    target_os = \"dragonfly\",\n    target_env = \"musl\",\n)) {\n    \"_RJEM_MALLOC_CONF\"\n} else {\n    \"MALLOC_CONF\"\n};\n\n/// Errors returned by [`dump_heap_profile`].\n#[derive(Debug, thiserror::Error)]\npub enum HeapDumpError {\n    #[error(\"tempfile path was not valid C string (non-utf8 or interior NUL)\")]\n    BadTempPath,\n    #[error(\"heap profiling is disabled; restart with {MALLOC_CONF_ENV}=prof:true to enable\")]\n    ProfilingDisabled,\n    #[error(\"jemalloc prof.dump failed: {0}\")]\n    Jemalloc(#[from] tikv_jemalloc_ctl::Error),\n    #[error(\"tempfile i/o: {0}\")]\n    Io(#[from] std::io::Error),\n    #[error(\"blocking task join: {0}\")]\n    Join(#[from] tokio::task::JoinError),\n}\n\n/// Trigger a jemalloc heap profile dump and return a streaming reader for\n/// the resulting `heap_v2` bytes.\n///\n/// Requires jemalloc built with `--enable-prof` (i.e. `tikv-jemallocator`\n/// `profiling` feature) AND the binary started with `prof:true` in the\n/// platform-appropriate `MALLOC_CONF` env var (or via a baked-in\n/// `malloc_conf` static — see [`DEFAULT_MALLOC_CONF`]). When profiling is","sourceCodeStart":74,"sourceCodeEnd":110,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/core/jemalloc_stats/src/lib.rs#L74-L110","documentation":"HeapDumpError::BadTempPath is returned by dump_heap_profile in the jemalloc_stats crate when the temporary file created for the heap profile dump cannot be passed to jemalloc as a C string. jemalloc's prof.dump option requires a NUL-terminated path, so the tempfile path must be valid UTF-8 with no interior NUL bytes. If either condition fails, the path is rejected before any dump is attempted.","triggerScenarios":"Calling dump_heap_profile() (or the pprof HTTP endpoint backed by it) on a system where the temp directory resolves to a path containing non-UTF-8 bytes or an embedded NUL character.","commonSituations":"TMPDIR or the OS temp-dir environment pointing at a directory with non-UTF-8 bytes; unusual locale setups in containers; paths constructed programmatically with embedded NULs.","solutions":["Ensure TMPDIR (and the OS temp directory) is a plain UTF-8 path without special characters and restart the process","Verify the environment with `echo $TMPDIR` and `printf %q`, correcting any odd bytes","If the path is genuinely valid, report a bug: the tempfile crate's path handling may need inspection"],"exampleFix":"// before\nTMPDIR=/tmp/naïve$'\\x01'dir myapp\n// after\nTMPDIR=/tmp myapp","handlingStrategy":"validation","validationCode":"fn temp_path_is_c_string() -> bool {\n    std::env::var(\"TMPDIR\").map(|d| std::path::Path::new(&d).is_dir() && !d.contains('\\0') && d.is_ascii()).unwrap_or(true)\n}","typeGuard":"fn valid_c_string(p: &std::path::Path) -> bool {\n    p.to_str().map(|s| !s.contains('\\0')).unwrap_or(false)\n}","tryCatchPattern":"match dump_heap_profile().await {\n    Err(HeapDumpError::BadTempPath) => eprintln!(\"fix TMPDIR: must be valid UTF-8 without NUL\"),\n    other => other?,\n}","preventionTips":["Keep TMPDIR a plain ASCII path","Avoid custom temp dirs with unicode/locale-dependent bytes in containers","Test heap-dump endpoints in the actual deployment environment"],"tags":["rust","jemalloc","heap-profiling","tempfile","encoding"],"backgroundTag":"invalid-argument-format","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}