On Sat, 01 Aug 2026 18:59:40 +0800 Eugene Mavick <[email protected]> wrote:
> When debugging use-after-free(UAF) bugs, knowing when the object reaches > 0 references and enters final release can significantly aid the > debugging process. > > There is currently no universal way to trace this information. > > This patch series implements tracing of the final puts in the > most widely used refcounting implementations, > refcount_t(and thus kref which uses it), and percpu-ref. > I have a question regarding the event group name. If this is related to refcount, wouldn't it be more appropriate to call it `refcount_final_put`? Even if it is currently used by `ref_trace`, it is fundamentally an event belonging to the refcount subsystem. I believe event names should be based on where the event occurs and what actually happens, rather than on who is using it. Thank you, > The tracepoint records three fields: > - caller: function that called the refcounting > function(refcount_sub_and_test, percpu_ref_put_many) > - ip: return address of the trace wrapper macro call > - obj: refcount object(struct percpu_ref, refcount_t) > > Signed-off-by: Eugene Mavick <[email protected]> > --- > Changes in v4: > ref-trace: > -remove fn > -add ip variable > -change trace wrapper macro respectively, _THIS_IP_ is used for ip variable > -change relevant code respect to fn removal and ip addition > -fix style issues in include/linux/ref_trace.h > -add new macro do_trace_ref_final_put_cond that only calls tracepoint if cond > is > true > lib/refcount.c: > -change from do_trace_ref_final_put to *_cond > -remove if statement above since _cond already performs the check > KUnit: > -change relevant code respect to fn removal and ip addition > -check if caller and ip are valid addresses > -change timeout from 10 jiffies to 10 seconds > -move didn't timeout assertion from before to after probe > unregistration, to prevent it from impacting next test > > Changes in v3: > include/trace/events/ref_trace.h kernel doc comments: > -caller of refcount function -> return address of refcount function > -ref_trace_final_put->do_ref_trace_final_put > lib/ref_trace.c: add include trace/events/ref_trace.h > kunit: > -change Kconfig depends from FTRACE->TRACEPOINTS > -EXPECT_FALSE->ASSERT_FALSE for calling percpu_ref_init > -add tracepoint_synchronise_unregister to test_exit macro > -added timeout to capture.count waiting > -remove noinline and __always_inline from function attributes > (added for testing, but accidentally submitted) > -add period to the end of Kconfig help text > v2 link: > https://lore.kernel.org/all/[email protected]/ > > Changes in v2: > -include/linux/ref_trace.h: change macro name, use direct tracepoint > call in macro to avoid double check > -add tracepoint to refcount_dec_if_one > -kunit: make significant improvements to design, fix critical bug, add test > case for > refcount_dec_if_one() > -Link to v1: > https://lore.kernel.org/r/[email protected] > > --- > Eugene Mavick (5): > tracing: add ref_trace_final_put tracepoint > refcount: add ref_trace_final_put tracepoint > percpu-refcount: add ref_trace_final_put trace > kunit: add test for ref_trace_final_put > MAINTAINERS: add entries for ref_trace_final_put > > MAINTAINERS | 3 + > include/linux/percpu-refcount.h | 5 +- > include/linux/ref_trace.h | 40 +++++++++++ > include/linux/refcount.h | 2 + > include/trace/events/ref_trace.h | 51 ++++++++++++++ > lib/Kconfig | 10 +++ > lib/Makefile | 2 + > lib/ref_trace.c | 13 ++++ > lib/refcount.c | 6 +- > lib/tests/Makefile | 1 + > lib/tests/ref_trace_kunit.c | 141 > +++++++++++++++++++++++++++++++++++++++ > 11 files changed, 272 insertions(+), 2 deletions(-) > --- > base-commit: df685633c3dbc67441cc86f1c3fee58de4652ba2 > change-id: 20260624-refcount-final-put-trace-49bd7c39bd5a > > Best regards, > -- > Eugene Mavick <[email protected]> > > -- Masami Hiramatsu (Google) <[email protected]>
