On Sat, 01 Aug 2026 18:59:40 +0800
Eugene Mavick <[email protected]> wrote:

> When debugging use-after-free(UAF) bugs, knowing when the object reaches
> 0 references and enters final release can significantly aid the
> debugging process.
> 
> There is currently no universal way to trace this information.
> 
> This patch series implements tracing of the final puts in the
> most widely used refcounting implementations,
> refcount_t(and thus kref which uses it), and percpu-ref.
> 

I have a question regarding the event group name. If this is related to
refcount, wouldn't it be more appropriate to call it `refcount_final_put`?
Even if it is currently used by `ref_trace`, it is fundamentally an event
belonging to the refcount subsystem.
I believe event names should be based on where the event occurs and what
actually happens, rather than on who is using it.

Thank you,

> The tracepoint records three fields:
> - caller: function that called the refcounting
>   function(refcount_sub_and_test, percpu_ref_put_many)
> - ip: return address of the trace wrapper macro call
> - obj: refcount object(struct percpu_ref, refcount_t)
> 
> Signed-off-by: Eugene Mavick <[email protected]>
> ---
> Changes in v4:
> ref-trace:
> -remove fn
> -add ip variable
> -change trace wrapper macro respectively, _THIS_IP_ is used for ip variable
> -change relevant code respect to fn removal and ip addition
> -fix style issues in include/linux/ref_trace.h
> -add new macro do_trace_ref_final_put_cond that only calls tracepoint if cond 
> is
>  true
> lib/refcount.c:
> -change from do_trace_ref_final_put to *_cond
> -remove if statement above since _cond already performs the check
> KUnit:
> -change relevant code respect to fn removal and ip addition
> -check if caller and ip are valid addresses
> -change timeout from 10 jiffies to 10 seconds
> -move didn't timeout assertion from before to after probe
>  unregistration, to prevent it from impacting next test
> 
> Changes in v3:
> include/trace/events/ref_trace.h kernel doc comments:
> -caller of refcount function -> return address of refcount function
> -ref_trace_final_put->do_ref_trace_final_put
> lib/ref_trace.c: add include trace/events/ref_trace.h
> kunit:
> -change Kconfig depends from FTRACE->TRACEPOINTS
> -EXPECT_FALSE->ASSERT_FALSE for calling percpu_ref_init
> -add tracepoint_synchronise_unregister to test_exit macro
> -added timeout to capture.count waiting
> -remove noinline and __always_inline from function attributes
>  (added for testing, but accidentally submitted)
> -add period to the end of Kconfig help text
> v2 link:
> https://lore.kernel.org/all/[email protected]/
> 
> Changes in v2:
> -include/linux/ref_trace.h: change macro name, use direct tracepoint
>  call in macro to avoid double check
> -add tracepoint to refcount_dec_if_one
> -kunit: make significant improvements to design, fix critical bug, add test 
> case for
>  refcount_dec_if_one()
> -Link to v1: 
> https://lore.kernel.org/r/[email protected]
> 
> ---
> Eugene Mavick (5):
>       tracing: add ref_trace_final_put tracepoint
>       refcount: add ref_trace_final_put tracepoint
>       percpu-refcount: add ref_trace_final_put trace
>       kunit: add test for ref_trace_final_put
>       MAINTAINERS: add entries for ref_trace_final_put
> 
>  MAINTAINERS                      |   3 +
>  include/linux/percpu-refcount.h  |   5 +-
>  include/linux/ref_trace.h        |  40 +++++++++++
>  include/linux/refcount.h         |   2 +
>  include/trace/events/ref_trace.h |  51 ++++++++++++++
>  lib/Kconfig                      |  10 +++
>  lib/Makefile                     |   2 +
>  lib/ref_trace.c                  |  13 ++++
>  lib/refcount.c                   |   6 +-
>  lib/tests/Makefile               |   1 +
>  lib/tests/ref_trace_kunit.c      | 141 
> +++++++++++++++++++++++++++++++++++++++
>  11 files changed, 272 insertions(+), 2 deletions(-)
> ---
> base-commit: df685633c3dbc67441cc86f1c3fee58de4652ba2
> change-id: 20260624-refcount-final-put-trace-49bd7c39bd5a
> 
> Best regards,
> -- 
> Eugene Mavick <[email protected]>
> 
> 


-- 
Masami Hiramatsu (Google) <[email protected]>

Reply via email to