* [PATCH v5 0/5] tracing: add refcount_final_put tracing
@ 2026-08-13 3:49 Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 1/5] tracing: add refcount_final_put tracepoint Eugene Mavick
` (4 more replies)
0 siblings, 5 replies; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
When debugging use-after-free(UAF) bugs, knowing when the object reaches
0 references and enters final release(final put) can significantly aid the
debugging process.
This patch series adds a tracepoint, refcount_final_put, with
compilation toggleable with CONFIG_REFCOUNT_TRACE_FINAL_PUT.
refcount_final_put fires when a reference
count reaches zero and the object enters its final release path.
refcount_final_put records three fields:
- caller: function that called the refcounting
function(refcount_sub_and_test, percpu_ref_put_many)
- ip: return address of trace wrapper macro call
- obj: refcount object(struct percpu_ref, refcount_t)
bloat-o-meter stats:
CONFIG_REFCOUNT_TRACE_FINAL_PUT=n :
Total: Before=24703933, After=24703933, chg +0.00%
CONFIG_REFCOUNT_TRACE_FINAL_PUT=y :
Total: Before=24703933, After=24764816, chg +0.25%
Alternatives to obtain this information require live reproduction, and
incur a significant performance cost, making them impractical to have
enabled on fuzzers like syzbot.
refcount functions performing final-puts are also inlined, further
complicating alternative dynamic tracing possibilities.
Debugging UAFs without final-put knowledge is possible but is often
significantly harder and requires broad code reading and mapping,
whereas knowing the final-put allows narrowing the scope, thus
decreasing time and effort required.
Local live reproduction and alternative tracing are time, hardware
resource, and manual effort exhaustive. Time-sensitive UAFs which
require many iterations to reproduce further worsen these requirements.
Remote-fuzzer report based UAF debugging is an incredibly frequent
occurence.
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
Changes in v5:
-rename ref_trace to refcount
-add CONFIG_REFCOUNT_TRACE_FINAL_PUT Kconfig option, due to high footprint
-improve cover letter, add bloat-o-meter statistics
v4: https://lore.kernel.org/r/20260801-refcount-final-put-trace-v4-0-2e58678f0ffd@mavick.dev
Changes in v4:
ref-trace:
-remove fn
-add ip variable
-change trace wrapper macro respectively, _THIS_IP_ is used for ip variable
-change relevant code respect to fn removal and ip addition
-fix style issues in include/linux/ref_trace.h
-add new macro do_trace_ref_final_put_cond that only calls tracepoint if cond is
true
lib/refcount.c:
-change from do_trace_ref_final_put to *_cond
-remove if statement above since _cond already performs the check
KUnit:
-change relevant code respect to fn removal and ip addition
-check if caller and ip are valid addresses
-change timeout from 10 jiffies to 10 seconds
-move didn't timeout assertion from before to after probe
unregistration, to prevent it from impacting next test
Changes in v3:
include/trace/events/ref_trace.h kernel doc comments:
-caller of refcount function -> return address of refcount function
-ref_trace_final_put->do_ref_trace_final_put
lib/ref_trace.c: add include trace/events/ref_trace.h
kunit:
-change Kconfig depends from FTRACE->TRACEPOINTS
-EXPECT_FALSE->ASSERT_FALSE for calling percpu_ref_init
-add tracepoint_synchronise_unregister to test_exit macro
-added timeout to capture.count waiting
-remove noinline and __always_inline from function attributes
(added for testing, but accidentally submitted)
-add period to the end of Kconfig help text
v2 link:
https://lore.kernel.org/all/20260710-refcount-final-put-trace-v2-0-557cfce860a2@mavick.dev/
Changes in v2:
-include/linux/ref_trace.h: change macro name, use direct tracepoint
call in macro to avoid double check
-add tracepoint to refcount_dec_if_one
-kunit: make significant improvements to design, fix critical bug, add test case for
refcount_dec_if_one()
-Link to v1: https://lore.kernel.org/r/20260705-refcount-final-put-trace-v1-0-0ae936edb750@mavick.dev
---
Eugene Mavick (5):
tracing: add refcount_final_put tracepoint
refcount: add refcount_final_put tracepoint
percpu-refcount: add refcount_final_put tracepoint
kunit: add test for refcount_final_put
MAINTAINERS: add entries for refcount_final_put trace
MAINTAINERS | 3 +
include/linux/percpu-refcount.h | 5 +-
include/linux/refcount.h | 2 +
include/linux/refcount_trace.h | 33 +++++++++
include/trace/events/refcount.h | 55 +++++++++++++++
lib/Kconfig | 18 +++++
lib/Makefile | 2 +
lib/refcount.c | 6 +-
lib/refcount_trace.c | 14 ++++
lib/tests/Makefile | 1 +
lib/tests/refcount_trace_kunit.c | 141 +++++++++++++++++++++++++++++++++++++++
11 files changed, 278 insertions(+), 2 deletions(-)
---
base-commit: df685633c3dbc67441cc86f1c3fee58de4652ba2
change-id: 20260624-refcount-final-put-trace-49bd7c39bd5a
Best regards,
--
Eugene Mavick <m@mavick.dev>
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v5 1/5] tracing: add refcount_final_put tracepoint
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
@ 2026-08-13 3:49 ` Eugene Mavick
2026-08-13 4:02 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 2/5] refcount: " Eugene Mavick
` (3 subsequent siblings)
4 siblings, 1 reply; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
Add refcount_final_put tracepoint and related core infrastructure
refcount_final_put fires when a reference
count reaches zero and the object enters its final release path.
The tracepoint records three fields:
- caller: function that called the refcounting
function(refcount_sub_and_test, percpu_ref_put_many)
- ip: return address of trace wrapper macro call
- obj: refcount object(struct percpu_ref, refcount_t)
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
include/linux/refcount_trace.h | 33 +++++++++++++++++++++++++
include/trace/events/refcount.h | 55 +++++++++++++++++++++++++++++++++++++++++
lib/Kconfig | 8 ++++++
lib/Makefile | 2 ++
lib/refcount_trace.c | 14 +++++++++++
5 files changed, 112 insertions(+)
diff --git a/include/linux/refcount_trace.h b/include/linux/refcount_trace.h
new file mode 100644
index 000000000000..6f8d0ba910f0
--- /dev/null
+++ b/include/linux/refcount_trace.h
@@ -0,0 +1,33 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#ifndef _LINUX_REFCOUNT_TRACE_H
+#define _LINUX_REFCOUNT_TRACE_H
+
+#include <linux/tracepoint-defs.h>
+#include <linux/instruction_pointer.h>
+
+#ifdef CONFIG_REFCOUNT_TRACE_FINAL_PUT
+/* Declare the tracepoint so tracepoint_enabled() can be used */
+DECLARE_TRACEPOINT(refcount_final_put);
+
+/* Wrapper function implemented in lib/ref_trace.c */
+extern void do_refcount_trace_final_put(unsigned long caller, unsigned long ip, const void *obj);
+
+#define do_trace_refcount_final_put(obj) \
+ do { \
+ if (tracepoint_enabled(refcount_final_put)) \
+ do_refcount_trace_final_put(_RET_IP_, _THIS_IP_, obj); \
+ } while (0)
+
+#define do_trace_refcount_final_put_cond(cond, obj) \
+ do { \
+ if (tracepoint_enabled(refcount_final_put) && cond) \
+ do_refcount_trace_final_put(_RET_IP_, _THIS_IP_, obj); \
+ } while (0)
+
+#else /* !CONFIG_REFCOUNT_TRACE_FINAL_PUT */
+extern void do_refcount_trace_final_put(unsigned long caller, unsigned long ip, const void *obj);
+#define do_trace_refcount_final_put(obj) do { } while (0)
+#define do_trace_refcount_final_put_cond(cond, obj) do { } while (0)
+#endif
+
+#endif /* _LINUX_REFCOUNT_TRACE_H */
diff --git a/include/trace/events/refcount.h b/include/trace/events/refcount.h
new file mode 100644
index 000000000000..a4dc23aff93b
--- /dev/null
+++ b/include/trace/events/refcount.h
@@ -0,0 +1,55 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#undef TRACE_SYSTEM
+#define TRACE_SYSTEM refcount
+
+#if !defined(_TRACE_REFCOUNT_H) || defined(TRACE_HEADER_MULTI_READ)
+#define _TRACE_REFCOUNT_H
+
+#include <linux/tracepoint.h>
+
+#ifdef CONFIG_REFCOUNT_TRACE_FINAL_PUT
+
+/**
+ * refcount_final_put - trace when a reference count reaches zero
+ * @caller: return address of refcount
+ * function(refcount_sub_and_test, percpu_ref_put_many)
+ * @ip: return address of trace wrapper macro call,
+ * inlining may cause it to be something else tho
+ * @obj: refcount object(struct percpu_ref, refcount_t)
+ *
+ * Tracepoint instrumentation can be added using the do_refcount_trace_final_put
+ * macro defined in include/linux/refcount_trace.h
+ * which uses _RET_IP_ and _THIS_IP_ for caller and ip arguments respectively,
+ * thus only requiring obj arg to be supplied
+ */
+TRACE_EVENT(refcount_final_put,
+
+ TP_PROTO(unsigned long caller, unsigned long ip, const void *obj),
+
+ TP_ARGS(caller, ip, obj),
+
+ TP_STRUCT__entry(
+ __field( unsigned long, caller )
+ __field( unsigned long, ip )
+ __field( const void *, obj )
+ ),
+
+ TP_fast_assign(
+ __entry->caller = caller;
+ __entry->ip = ip;
+ __entry->obj = obj;
+ ),
+
+ TP_printk("caller=%pS ip=%pS obj=%p",
+ (void *)__entry->caller,
+ (void *)__entry->ip,
+ __entry->obj
+ )
+);
+
+#endif /* CONFIG_REFCOUNT_TRACE_FINAL_PUT */
+
+#endif /* _TRACE_REFCOUNT_H */
+
+/* This part must be outside protection */
+#include <trace/define_trace.h>
diff --git a/lib/Kconfig b/lib/Kconfig
index 00a9509636c1..12bc59515a3e 100644
--- a/lib/Kconfig
+++ b/lib/Kconfig
@@ -52,6 +52,14 @@ config PACKING_KUNIT_TEST
When in doubt, say N.
+config REFCOUNT_TRACE_FINAL_PUT
+ bool "Trace final puts on multiple refcount implementations"
+ depends on TRACEPOINTS && DEBUG_KERNEL
+ help
+ Trace when a refcount implementation considers refcounted object dead.
+
+ If unsure, say N.
+
config BITREVERSE
tristate
diff --git a/lib/Makefile b/lib/Makefile
index f33a24bf1c19..e75e88f0c870 100644
--- a/lib/Makefile
+++ b/lib/Makefile
@@ -335,3 +335,5 @@ CONTEXT_ANALYSIS_test_context-analysis.o := y
obj-$(CONFIG_CONTEXT_ANALYSIS_TEST) += test_context-analysis.o
subdir-$(CONFIG_FORTIFY_SOURCE) += test_fortify
+
+obj-$(CONFIG_REFCOUNT_TRACE_FINAL_PUT) += refcount_trace.o
diff --git a/lib/refcount_trace.c b/lib/refcount_trace.c
new file mode 100644
index 000000000000..2476bb5f2f60
--- /dev/null
+++ b/lib/refcount_trace.c
@@ -0,0 +1,14 @@
+// SPDX-License-Identifier: GPL-2.0
+#define CREATE_TRACE_POINTS
+#include <trace/events/refcount.h>
+#include <linux/refcount_trace.h>
+
+//Wrapper function for functions defined entirely in header files
+void do_refcount_trace_final_put(unsigned long caller,
+ unsigned long ip,
+ const void *obj)
+{
+ trace_call__refcount_final_put(caller, ip, obj);
+}
+EXPORT_SYMBOL_GPL(do_refcount_trace_final_put);
+EXPORT_TRACEPOINT_SYMBOL_GPL(refcount_final_put);
--
2.51.2
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH v5 2/5] refcount: add refcount_final_put tracepoint
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 1/5] tracing: add refcount_final_put tracepoint Eugene Mavick
@ 2026-08-13 3:49 ` Eugene Mavick
2026-08-13 3:59 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 3/5] percpu-refcount: " Eugene Mavick
` (2 subsequent siblings)
4 siblings, 1 reply; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
Add the refcount_final_put tracepoint to __refcount_sub_and_test()
and refcount_dec_if_one()
refcount_final_put fires when a reference
count reaches zero and the object enters its final release path.
refcount_final_put records three fields:
- caller: function that called the refcounting
function(refcount_sub_and_test, percpu_ref_put_many)
- ip: return address of trace wrapper macro call
- obj: refcount object(struct percpu_ref, refcount_t)
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
include/linux/refcount.h | 2 ++
lib/refcount.c | 6 +++++-
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/include/linux/refcount.h b/include/linux/refcount.h
index ba7657ced281..23291a31d1be 100644
--- a/include/linux/refcount.h
+++ b/include/linux/refcount.h
@@ -107,6 +107,7 @@
#include <linux/limits.h>
#include <linux/refcount_types.h>
#include <linux/spinlock_types.h>
+#include <linux/refcount_trace.h>
struct mutex;
@@ -393,6 +394,7 @@ bool __refcount_sub_and_test(int i, refcount_t *r, int *oldp)
if (old > 0 && old == i) {
smp_acquire__after_ctrl_dep();
+ do_trace_refcount_final_put(r);
return true;
}
diff --git a/lib/refcount.c b/lib/refcount.c
index a207a8f22b3c..8b148b576503 100644
--- a/lib/refcount.c
+++ b/lib/refcount.c
@@ -7,6 +7,7 @@
#include <linux/refcount.h>
#include <linux/spinlock.h>
#include <linux/bug.h>
+#include <linux/refcount_trace.h>
#define REFCOUNT_WARN(str) WARN_ONCE(1, "refcount_t: " str ".\n")
@@ -56,7 +57,10 @@ bool refcount_dec_if_one(refcount_t *r)
{
int val = 1;
- return atomic_try_cmpxchg_release(&r->refs, &val, 0);
+ bool ret = atomic_try_cmpxchg_release(&r->refs, &val, 0);
+
+ do_trace_refcount_final_put_cond(ret, r);
+ return ret;
}
EXPORT_SYMBOL(refcount_dec_if_one);
--
2.51.2
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH v5 3/5] percpu-refcount: add refcount_final_put tracepoint
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 1/5] tracing: add refcount_final_put tracepoint Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 2/5] refcount: " Eugene Mavick
@ 2026-08-13 3:49 ` Eugene Mavick
2026-08-13 4:02 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 4/5] kunit: add test for refcount_final_put Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 5/5] MAINTAINERS: add entries for refcount_final_put trace Eugene Mavick
4 siblings, 1 reply; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
Add the refcount_final_put tracepoint to percpu_ref_put_many().
The tracepoint fires when the atomic counter reaches zero in the
atomic fallback path (after percpu_ref_kill() has been called).
refcount_final_put records three fields:
- caller: function that called the refcounting
function(refcount_sub_and_test, percpu_ref_put_many)
- ip: return address of trace wrapper macro call
- obj: refcount object(struct percpu_ref, refcount_t)
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
include/linux/percpu-refcount.h | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/include/linux/percpu-refcount.h b/include/linux/percpu-refcount.h
index d73a1c08c3e3..244992b2f746 100644
--- a/include/linux/percpu-refcount.h
+++ b/include/linux/percpu-refcount.h
@@ -55,6 +55,7 @@
#include <linux/rcupdate.h>
#include <linux/types.h>
#include <linux/gfp.h>
+#include <linux/refcount_trace.h>
struct percpu_ref;
typedef void (percpu_ref_func_t)(struct percpu_ref *);
@@ -331,8 +332,10 @@ static inline void percpu_ref_put_many(struct percpu_ref *ref, unsigned long nr)
if (__ref_is_percpu(ref, &percpu_count))
this_cpu_sub(*percpu_count, nr);
- else if (unlikely(atomic_long_sub_and_test(nr, &ref->data->count)))
+ else if (unlikely(atomic_long_sub_and_test(nr, &ref->data->count))) {
+ do_trace_refcount_final_put(ref);
ref->data->release(ref);
+ }
rcu_read_unlock();
}
--
2.51.2
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH v5 4/5] kunit: add test for refcount_final_put
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
` (2 preceding siblings ...)
2026-08-13 3:49 ` [PATCH v5 3/5] percpu-refcount: " Eugene Mavick
@ 2026-08-13 3:49 ` Eugene Mavick
2026-08-13 4:01 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 5/5] MAINTAINERS: add entries for refcount_final_put trace Eugene Mavick
4 siblings, 1 reply; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
Add a KUnit test suite for the refcount_final_put tracepoint.
The test registers a probe function and triggers both refcount_t and
percpu_ref final put paths, verifying that the tracepoint fires
correctly and that the recorded fields match expected values.
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
lib/Kconfig | 10 +++
lib/tests/Makefile | 1 +
lib/tests/refcount_trace_kunit.c | 141 +++++++++++++++++++++++++++++++++++++++
3 files changed, 152 insertions(+)
diff --git a/lib/Kconfig b/lib/Kconfig
index 12bc59515a3e..ee12e8f95158 100644
--- a/lib/Kconfig
+++ b/lib/Kconfig
@@ -60,6 +60,16 @@ config REFCOUNT_TRACE_FINAL_PUT
If unsure, say N.
+config REFCOUNT_TRACE_KUNIT_TEST
+ tristate "refcount trace kunit test" if !KUNIT_ALL_TESTS
+ depends on REFCOUNT_TRACE_FINAL_PUT && KUNIT && TRACEPOINTS
+ default KUNIT_ALL_TESTS
+ help
+ This option enables the KUnit test suite for the refcount_final_put
+ tracepoint.
+
+ If unsure, say N.
+
config BITREVERSE
tristate
diff --git a/lib/tests/Makefile b/lib/tests/Makefile
index 7e9c2fa52e35..1ef41c0b6a0c 100644
--- a/lib/tests/Makefile
+++ b/lib/tests/Makefile
@@ -57,5 +57,6 @@ obj-$(CONFIG_USERCOPY_KUNIT_TEST) += usercopy_kunit.o
obj-$(CONFIG_UTIL_MACROS_KUNIT) += util_macros_kunit.o
obj-$(CONFIG_RATELIMIT_KUNIT_TEST) += test_ratelimit.o
obj-$(CONFIG_UUID_KUNIT_TEST) += uuid_kunit.o
+obj-$(CONFIG_REFCOUNT_TRACE_KUNIT_TEST) += refcount_trace_kunit.o
obj-$(CONFIG_TEST_RUNTIME_MODULE) += module/
diff --git a/lib/tests/refcount_trace_kunit.c b/lib/tests/refcount_trace_kunit.c
new file mode 100644
index 000000000000..a57e9e4cfa42
--- /dev/null
+++ b/lib/tests/refcount_trace_kunit.c
@@ -0,0 +1,141 @@
+// SPDX-License-Identifier: GPL-2.0
+#include <linux/kernel.h>
+#include <kunit/test.h>
+#include <linux/compiler_attributes.h>
+#include <linux/wait_bit.h>
+#include <linux/instruction_pointer.h>
+#include <linux/kallsyms.h>
+#include <linux/jiffies.h>
+#include <linux/percpu-refcount.h>
+#include <linux/refcount.h>
+#include <linux/types.h>
+#include <linux/atomic.h>
+#include <trace/events/refcount.h>
+
+struct data {
+ unsigned long caller;
+ unsigned long ip;
+ const void *obj;
+ atomic_t count;
+};
+
+struct data capture;
+
+const void *chk_obj;
+
+#define test_init() \
+ do { \
+ KUNIT_EXPECT_FALSE( \
+ test, register_trace_refcount_final_put(probe, NULL)); \
+ \
+ atomic_set_release(&capture.count, 0); \
+ \
+ chk_obj = &obj; \
+ } while (0)
+
+
+#define test_exit() \
+ do { \
+ /* wait for probe completion */ \
+ int notimeout = wait_var_event_timeout( \
+ &capture.count, \
+ atomic_read_acquire(&capture.count), \
+ msecs_to_jiffies(10000) \
+ ); \
+ \
+ unregister_trace_refcount_final_put(probe, NULL); \
+ tracepoint_synchronize_unregister(); \
+ \
+ KUNIT_ASSERT_TRUE(test, notimeout); \
+ \
+ KUNIT_EXPECT_EQ(test, atomic_read_acquire(&capture.count), 1); \
+ \
+ KUNIT_EXPECT_TRUE(test, __kernel_text_address(capture.caller)); \
+ KUNIT_EXPECT_TRUE(test, __kernel_text_address(capture.ip)); \
+ \
+ KUNIT_EXPECT_PTR_EQ(test, capture.obj, &obj); \
+ } while (0)
+
+static void probe(
+ void *ignore,
+ unsigned long caller,
+ unsigned long ip,
+ const void *obj)
+{
+ //prevent non test func final_puts from changing captured values
+ if (chk_obj != obj)
+ return;
+
+ capture.caller = caller;
+ capture.ip = ip;
+ capture.obj = obj;
+
+ atomic_inc_return_release(&capture.count); //increase count
+}
+
+static void test_refcount_sub_and_test(struct kunit *test)
+{
+ refcount_t obj;
+
+ test_init();
+ refcount_set(&obj, 2);
+
+ KUNIT_EXPECT_FALSE(test, refcount_dec_and_test(&obj));
+ KUNIT_EXPECT_TRUE(test, refcount_dec_and_test(&obj));
+
+ test_exit();
+}
+
+static void test_refcount_dec_if_one(struct kunit *test)
+{
+ refcount_t obj;
+
+ test_init();
+ refcount_set(&obj, 2);
+
+ KUNIT_EXPECT_FALSE(test, refcount_dec_and_test(&obj));
+ KUNIT_EXPECT_TRUE(test, refcount_dec_if_one(&obj));
+
+ test_exit();
+}
+static void dummy_release(struct percpu_ref *ref) {}
+
+static void test_percpu_ref_put_many(struct kunit *test)
+{
+ struct percpu_ref obj;
+
+ test_init();
+
+ KUNIT_ASSERT_FALSE(test, percpu_ref_init(&obj, dummy_release, 0, GFP_KERNEL));
+
+ percpu_ref_get(&obj);
+ percpu_ref_get(&obj);
+
+ percpu_ref_put(&obj);
+ percpu_ref_put(&obj);
+
+ percpu_ref_switch_to_atomic_sync(&obj);
+
+ percpu_ref_put(&obj);
+
+ test_exit();
+ percpu_ref_exit(&obj);
+}
+
+static struct kunit_case refcount_trace_test_cases[] = {
+ KUNIT_CASE(test_refcount_sub_and_test),
+ KUNIT_CASE(test_refcount_dec_if_one),
+ KUNIT_CASE(test_percpu_ref_put_many),
+ {}
+};
+
+static struct kunit_suite refcount_trace_test_suite = {
+ .name = "refcount-trace",
+ .test_cases = refcount_trace_test_cases
+};
+
+kunit_test_suites(&refcount_trace_test_suite);
+
+MODULE_AUTHOR("Eugene Mavick <m@mavick.dev>");
+MODULE_DESCRIPTION("KUnit test for ref_trace");
+MODULE_LICENSE("GPL");
--
2.51.2
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH v5 5/5] MAINTAINERS: add entries for refcount_final_put trace
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
` (3 preceding siblings ...)
2026-08-13 3:49 ` [PATCH v5 4/5] kunit: add test for refcount_final_put Eugene Mavick
@ 2026-08-13 3:49 ` Eugene Mavick
4 siblings, 0 replies; 10+ messages in thread
From: Eugene Mavick @ 2026-08-13 3:49 UTC (permalink / raw)
To: Will Deacon, Peter Zijlstra, Boqun Feng, Mark Rutland, Gary Guo,
Steven Rostedt, Masami Hiramatsu, Mathieu Desnoyers,
Andrew Morton, Dennis Zhou, Tejun Heo, Christoph Lameter,
Dmitry Vyukov, Andrey Konovalov, Alexander Potapenko, Marco Elver,
Andrey Ryabinin
Cc: linux-kernel, linux-trace-kernel, linux-mm, kasan-dev,
Eugene Mavick
Add new files added in the patch series to MAINTAINERS
Signed-off-by: Eugene Mavick <m@mavick.dev>
---
MAINTAINERS | 3 +++
1 file changed, 3 insertions(+)
diff --git a/MAINTAINERS b/MAINTAINERS
index 10e8253181d3..c37e4cd0e4ff 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -4210,7 +4210,10 @@ S: Maintained
F: Documentation/atomic_*.txt
F: arch/*/include/asm/atomic*.h
F: include/*/atomic*.h
+F: include/linux/refcount_trace.h
F: include/linux/refcount.h
+F: lib/refcount_trace.c
+F: lib/tests/refcount_trace_kunit.c
F: scripts/atomic/
F: rust/kernel/sync/atomic.rs
F: rust/kernel/sync/atomic/
--
2.51.2
^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [PATCH v5 2/5] refcount: add refcount_final_put tracepoint
2026-08-13 3:49 ` [PATCH v5 2/5] refcount: " Eugene Mavick
@ 2026-08-13 3:59 ` sashiko-bot
0 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-08-13 3:59 UTC (permalink / raw)
To: Eugene Mavick; +Cc: linux-trace-kernel
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Exporting the trace wrapper via GPL-only symbols inside fundamental static inline refcount primitives breaks the ability of non-GPL modules to load.
- [Medium] The `caller` and `ip` fields recorded by the tracepoint yield fundamentally inconsistent addresses depending on whether the calling function is evaluated as inline or out-of-line.
--
--- Patch [2]: [PATCH v5 2/5] refcount: add refcount_final_put tracepoint ---
commit 89e648b43dd0e3f81f4dd1bfaaa093ab2953cba7
Author: Eugene Mavick <m@mavick.dev>
refcount: add refcount_final_put tracepoint
Add the refcount_final_put tracepoint to __refcount_sub_and_test()
and refcount_dec_if_one()
refcount_final_put fires when a reference
count reaches zero and the object enters its final release path.
> diff --git a/include/linux/refcount.h b/include/linux/refcount.h
> index ba7657ced2817..23291a31d1be2 100644
> --- a/include/linux/refcount.h
> +++ b/include/linux/refcount.h
[ ... ]
> @@ -393,6 +394,7 @@ bool __refcount_sub_and_test(int i, refcount_t *r, int *oldp)
>
> if (old > 0 && old == i) {
> smp_acquire__after_ctrl_dep();
> + do_trace_refcount_final_put(r);
[Severity: High]
Does this break out-of-tree non-GPL modules?
Since __refcount_sub_and_test() is a fundamental inline primitive, embedding
the tracepoint macro here forces callers to resolve the GPL-only tracepoint
symbols. This will cause non-GPL modules to fail to load when they include
<linux/refcount.h> and call this function.
[Severity: Medium]
Will this record inconsistent instruction pointers depending on whether the
function is evaluated inline?
Because __refcount_sub_and_test() is static inline, _RET_IP_ will evaluate to
the return address of the module invoking the refcount API (the caller's
caller), while _THIS_IP_ evaluates to the caller.
> return true;
> }
>
> diff --git a/lib/refcount.c b/lib/refcount.c
> index a207a8f22b3ca..8b148b5765037 100644
> --- a/lib/refcount.c
> +++ b/lib/refcount.c
[ ... ]
> @@ -56,7 +57,10 @@ bool refcount_dec_if_one(refcount_t *r)
> {
> int val = 1;
>
> - return atomic_try_cmpxchg_release(&r->refs, &val, 0);
> + bool ret = atomic_try_cmpxchg_release(&r->refs, &val, 0);
> +
> + do_trace_refcount_final_put_cond(ret, r);
[Severity: Medium]
In this out-of-line context, _RET_IP_ evaluates to the immediate caller.
Does this mean the caller and ip fields recorded by the tracepoint will yield
fundamentally inconsistent addresses compared to the inline usage in
__refcount_sub_and_test()?
> + return ret;
> }
> EXPORT_SYMBOL(refcount_dec_if_one);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-refcount-final-put-trace-v5-0-6e8bf8a38b31@mavick.dev?part=2
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v5 4/5] kunit: add test for refcount_final_put
2026-08-13 3:49 ` [PATCH v5 4/5] kunit: add test for refcount_final_put Eugene Mavick
@ 2026-08-13 4:01 ` sashiko-bot
0 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-08-13 4:01 UTC (permalink / raw)
To: Eugene Mavick; +Cc: linux-trace-kernel
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] KUNIT_ASSERT_* usage bypasses test cleanup on failure, permanently leaking memory and leaving a global trace probe registered.
- [Medium] Shared test state is initialized after the global tracepoint probe is registered, creating a data race with concurrent kernel threads.
- [Medium] Missing wake_up_var in the tracepoint probe causes a 10-second hang on test failure.
--
--- Patch [4]: [PATCH v5 4/5] kunit: add test for refcount_final_put ---
commit fef38efeda6f44aecbf042d2f2cbb9c0d0c7ccb4
Author: Eugene Mavick <m@mavick.dev>
kunit: add test for refcount_final_put
Add a KUnit test suite for the refcount_final_put tracepoint.
The test registers a probe function and triggers both refcount_t and
percpu_ref final put paths, verifying that the tracepoint fires
correctly and that the recorded fields match expected values.
> diff --git a/lib/tests/refcount_trace_kunit.c b/lib/tests/refcount_trace_kunit.c
> new file mode 100644
> index 0000000000000..a57e9e4cfa427
> --- /dev/null
> +++ b/lib/tests/refcount_trace_kunit.c
> @@ -0,0 +1,141 @@
[ ... ]
> +struct data {
> + unsigned long caller;
> + unsigned long ip;
> + const void *obj;
> + atomic_t count;
> +};
> +
> +struct data capture;
> +
> +const void *chk_obj;
> +
> +#define test_init() \
> + do { \
> + KUNIT_EXPECT_FALSE( \
> + test, register_trace_refcount_final_put(probe, NULL)); \
> + \
> + atomic_set_release(&capture.count, 0); \
> + \
> + chk_obj = &obj; \
> + } while (0)
[Severity: Medium]
Does registering this system-wide tracepoint before initializing
capture.count and chk_obj create a data race?
If a concurrent kernel thread triggers a refcount final put immediately
after register_trace_refcount_final_put() succeeds, it will execute probe()
and locklessly read chk_obj before the test thread initializes it here.
Would it be safer to initialize the test state variables prior to
registering the probe?
> +
> +
> +#define test_exit() \
> + do { \
> + /* wait for probe completion */ \
> + int notimeout = wait_var_event_timeout( \
> + &capture.count, \
> + atomic_read_acquire(&capture.count), \
> + msecs_to_jiffies(10000) \
> + ); \
[Severity: Medium]
Will this wait unconditionally hang for the full 10-second timeout on a
test failure?
The test thread waits here for capture.count to change, but looking at
probe(), the state is incremented with atomic_inc_return_release() without
a corresponding wake_up_var(&capture.count).
If the tracepoint fails to fire synchronously, does the missing wakeup
leave the thread permanently sleeping until the timeout expires?
> + \
> + unregister_trace_refcount_final_put(probe, NULL); \
> + tracepoint_synchronize_unregister(); \
> + \
> + KUNIT_ASSERT_TRUE(test, notimeout); \
[Severity: High]
Is it safe to use KUNIT_ASSERT_TRUE() here before the test cleanup has
finished?
If this assertion fails (e.g. the wait times out), the test aborts
immediately and skips the remainder of test_exit(). For tests like
test_percpu_ref_put_many(), this means percpu_ref_exit() is never called,
resulting in a memory leak.
> + \
> + KUNIT_EXPECT_EQ(test, atomic_read_acquire(&capture.count), 1); \
[ ... ]
> +static void test_percpu_ref_put_many(struct kunit *test)
> +{
> + struct percpu_ref obj;
> +
> + test_init();
> +
> + KUNIT_ASSERT_FALSE(test, percpu_ref_init(&obj, dummy_release, 0, GFP_KERNEL));
[Severity: High]
Does using KUNIT_ASSERT_FALSE() here risk leaving the global trace probe
permanently registered?
If percpu_ref_init() fails, KUNIT_ASSERT_FALSE() will abort the test execution
and skip test_exit(). This leaves the probe function registered globally.
When the KUnit module is later unloaded, any subsequent refcount final put
in the system will invoke the freed probe function, causing a kernel panic.
Should this test use kunit_add_action() for deferred cleanup to ensure
the tracepoint is always unregistered?
> +
> + percpu_ref_get(&obj);
> + percpu_ref_get(&obj);
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-refcount-final-put-trace-v5-0-6e8bf8a38b31@mavick.dev?part=4
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v5 1/5] tracing: add refcount_final_put tracepoint
2026-08-13 3:49 ` [PATCH v5 1/5] tracing: add refcount_final_put tracepoint Eugene Mavick
@ 2026-08-13 4:02 ` sashiko-bot
0 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-08-13 4:02 UTC (permalink / raw)
To: Eugene Mavick; +Cc: linux-trace-kernel
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [Medium] The `do_trace_refcount_final_put_cond` macro does not parenthesize its `cond` parameter, which can lead to logical errors and bypass the tracepoint static branch.
- [Medium] The refcount_final_put tracepoint is dead code because no callers were added to invoke it.
- [Low] Missing `<linux/export.h>` in `lib/refcount_trace.c`.
- [Low] Incorrect file name referenced in comment for the trace wrapper implementation.
--
--- Patch [1]: [PATCH v5 1/5] tracing: add refcount_final_put tracepoint ---
commit 6fe677465a197120927dfba704ab4c4aff5f134a
Author: Eugene Mavick <m@mavick.dev>
tracing: add refcount_final_put tracepoint
Add refcount_final_put tracepoint and related core infrastructure
refcount_final_put fires when a reference
count reaches zero and the object enters its final release path.
> The tracepoint records three fields:
> - caller: function that called the refcounting
> function(refcount_sub_and_test, percpu_ref_put_many)
[Severity: Medium]
Are there missing callers for the tracepoint macro?
The commit message mentions that the tracepoint records the caller function,
such as refcount_sub_and_test or percpu_ref_put_many, but this patch doesn't
add any calls to do_trace_refcount_final_put() in the refcount release paths.
This leaves the tracepoint inactive.
> diff --git a/include/linux/refcount_trace.h b/include/linux/refcount_trace.h
> new file mode 100644
> index 0000000000000..6f8d0ba910f05
> --- /dev/null
> +++ b/include/linux/refcount_trace.h
> @@ -0,0 +1,33 @@
> +/* SPDX-License-Identifier: GPL-2.0 */
> +#ifndef _LINUX_REFCOUNT_TRACE_H
> +#define _LINUX_REFCOUNT_TRACE_H
> +
> +#include <linux/tracepoint-defs.h>
> +#include <linux/instruction_pointer.h>
> +
> +#ifdef CONFIG_REFCOUNT_TRACE_FINAL_PUT
> +/* Declare the tracepoint so tracepoint_enabled() can be used */
> +DECLARE_TRACEPOINT(refcount_final_put);
> +
> +/* Wrapper function implemented in lib/ref_trace.c */
[Severity: Low]
This isn't a bug, but there's a typo in the filename here.
The wrapper is implemented in lib/refcount_trace.c, not lib/ref_trace.c.
> +extern void do_refcount_trace_final_put(unsigned long caller, unsigned long ip, const void *obj);
> +
> +#define do_trace_refcount_final_put(obj) \
> + do { \
> + if (tracepoint_enabled(refcount_final_put)) \
> + do_refcount_trace_final_put(_RET_IP_, _THIS_IP_, obj); \
> + } while (0)
> +
> +#define do_trace_refcount_final_put_cond(cond, obj) \
> + do { \
> + if (tracepoint_enabled(refcount_final_put) && cond) \
[Severity: Medium]
Should cond be wrapped in parentheses here?
If a caller passes a condition containing a logical OR, such as a || b,
operator precedence would cause this to evaluate as:
(tracepoint_enabled(...) && a) || b
If b is true, the trace wrapper would be invoked unconditionally even when the
tracepoint is disabled, bypassing the static key optimization.
> + do_refcount_trace_final_put(_RET_IP_, _THIS_IP_, obj); \
> + } while (0)
[ ... ]
> diff --git a/lib/refcount_trace.c b/lib/refcount_trace.c
> new file mode 100644
> index 0000000000000..2476bb5f2f603
> --- /dev/null
> +++ b/lib/refcount_trace.c
> @@ -0,0 +1,14 @@
> +// SPDX-License-Identifier: GPL-2.0
> +#define CREATE_TRACE_POINTS
> +#include <trace/events/refcount.h>
> +#include <linux/refcount_trace.h>
> +
[Severity: Low]
Should this file include <linux/export.h>?
It uses EXPORT_SYMBOL_GPL and EXPORT_TRACEPOINT_SYMBOL_GPL below. Relying on
implicit inclusions can sometimes cause build failures on different
architectures or configurations.
> +//Wrapper function for functions defined entirely in header files
> +void do_refcount_trace_final_put(unsigned long caller,
> + unsigned long ip,
> + const void *obj)
> +{
> + trace_call__refcount_final_put(caller, ip, obj);
> +}
> +EXPORT_SYMBOL_GPL(do_refcount_trace_final_put);
> +EXPORT_TRACEPOINT_SYMBOL_GPL(refcount_final_put);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-refcount-final-put-trace-v5-0-6e8bf8a38b31@mavick.dev?part=1
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v5 3/5] percpu-refcount: add refcount_final_put tracepoint
2026-08-13 3:49 ` [PATCH v5 3/5] percpu-refcount: " Eugene Mavick
@ 2026-08-13 4:02 ` sashiko-bot
0 siblings, 0 replies; 10+ messages in thread
From: sashiko-bot @ 2026-08-13 4:02 UTC (permalink / raw)
To: Eugene Mavick; +Cc: linux-trace-kernel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The tracepoint incorrectly uses `_RET_IP_` in a `static inline` function, causing it to report the caller's caller instead of the actual caller depending on compiler inlining.
--
--- Patch [3]: [PATCH v5 3/5] percpu-refcount: add refcount_final_put tracepoint ---
commit 9f895c01ce2cdf26a289904e12ffb409aa7dc2a0
Author: Eugene Mavick <m@mavick.dev>
percpu-refcount: add refcount_final_put tracepoint
This commit adds the refcount_final_put tracepoint to the atomic fallback
path in percpu_ref_put_many(). It fires when the atomic counter reaches
zero, recording the caller function, the instruction pointer, and the
refcount object.
> diff --git a/include/linux/percpu-refcount.h b/include/linux/percpu-refcount.h
> index d73a1c08c3e3c..244992b2f746e 100644
> --- a/include/linux/percpu-refcount.h
> +++ b/include/linux/percpu-refcount.h
[ ... ]
> @@ -331,8 +332,10 @@ static inline void percpu_ref_put_many(struct percpu_ref *ref, unsigned long nr)
>
> if (__ref_is_percpu(ref, &percpu_count))
> this_cpu_sub(*percpu_count, nr);
> - else if (unlikely(atomic_long_sub_and_test(nr, &ref->data->count)))
> + else if (unlikely(atomic_long_sub_and_test(nr, &ref->data->count))) {
> + do_trace_refcount_final_put(ref);
[Severity: Medium]
Since percpu_ref_put_many() is a static inline function, won't using _RET_IP_
inside the trace macro evaluate to the caller's caller when inlined?
When inlined by the compiler, _RET_IP_ (which expands to
__builtin_return_address(0)) will yield the instruction pointer of the
enclosing function rather than the caller of percpu_ref_put_many().
Could the instruction pointer be passed as an explicit argument from the call
site instead?
> ref->data->release(ref);
> + }
>
> rcu_read_unlock();
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813-refcount-final-put-trace-v5-0-6e8bf8a38b31@mavick.dev?part=3
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-08-13 4:02 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-13 3:49 [PATCH v5 0/5] tracing: add refcount_final_put tracing Eugene Mavick
2026-08-13 3:49 ` [PATCH v5 1/5] tracing: add refcount_final_put tracepoint Eugene Mavick
2026-08-13 4:02 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 2/5] refcount: " Eugene Mavick
2026-08-13 3:59 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 3/5] percpu-refcount: " Eugene Mavick
2026-08-13 4:02 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 4/5] kunit: add test for refcount_final_put Eugene Mavick
2026-08-13 4:01 ` sashiko-bot
2026-08-13 3:49 ` [PATCH v5 5/5] MAINTAINERS: add entries for refcount_final_put trace Eugene Mavick
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.