All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record
@ 2026-08-13 17:02 Ricardo Robaina
  2026-08-13 17:02 ` [PATCH 01/13] " Ricardo Robaina
                   ` (13 more replies)
  0 siblings, 14 replies; 28+ messages in thread
From: Ricardo Robaina @ 2026-08-13 17:02 UTC (permalink / raw)
  To: audit, linux-kernel, linux-alpha, linux-arm-kernel, linux-csky,
	linux-mips, linux-openrisc, linux-parisc, linux-sh, sparclinux,
	linux-um, bpf
  Cc: paul, eparis, sgrubb, oleg, richard.henderson, mattst88, linmag7,
	linux, catalin.marinas, will, guoren, monstr, tsbogend, jonas,
	stefan.kristiansson, shorne, James.Bottomley, deller, ysato,
	dalias, glaubitz, davem, andreas, richard, anton.ivanov, johannes,
	chris, jcmvbkbc, tglx, peterz, luto, Ricardo Robaina

The SYSCALL record currently logs only four of the six syscall
arguments (a0-a3), silently discarding the remaining two. This
leads to the need for auxiliary records when audit-relevant
data lands in the 5th or 6th argument of a syscall.

This series extends the SYSCALL record to log all six arguments,
by adding arguments a4 and a5 inline within the existing record.

The audit testsuite runs successfully:

 # make test
 make -C tests test
 chmod +x */test
 Running as   user    root
        with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
        on   system  Fedora

 amcast_joinpart/test ................. ok   
 backlog_wait_time_actual_reset/test .. ok   
 bpf/test ............................. ok   
 coredump/test ........................ ok   
 exec_execve/test ..................... ok   
 exec_name/test ....................... ok     
 fanotify/test ........................ ok   
 field_compare/test ................... ok     
 file_create/test ..................... ok   
 file_delete/test ..................... ok   
 file_permission/test ................. ok   
 file_rename/test ..................... ok   
 filter_device/test ................... ok     
 filter_exclude/test .................. ok     
 filter_exit/test ..................... ok   
 filter_inode/test .................... ok   
 filter_saddr_fam/test ................ ok   
 filter_sessionid/test ................ ok   
 io_uring/test ........................ ok   
 login_tty/test ....................... ok   
 lost_reset/test ...................... ok   
 netfilter_pkt/test ................... ok     
 signal/test .......................... ok   
 syscalls_file/test ................... ok   
 syscall_module/test .................. ok   
 syscall_socketcall/test .............. ok   
 time_change/test ..................... ok     
 user_msg/test ........................ ok   
 All tests successful.
 Result: PASS

Ricardo Robaina (13):
  audit: log all six syscall arguments in the SYSCALL record
  alpha: pass all six syscall args to audit_syscall_entry()
  arm: pass all six syscall args to audit_syscall_entry()
  arm64: pass all six syscall args to audit_syscall_entry()
  csky: pass all six syscall args to audit_syscall_entry()
  microblaze: pass all six syscall args to audit_syscall_entry()
  mips: pass all six syscall args to audit_syscall_entry()
  openrisc: pass all six syscall args to audit_syscall_entry()
  parisc: pass all six syscall args to audit_syscall_entry()
  sh: pass all six syscall args to audit_syscall_entry()
  sparc64: pass all six syscall args to audit_syscall_entry()
  um: pass all six syscall args to audit_syscall_entry()
  xtensa: pass all six syscall args to audit_syscall_entry()

 arch/alpha/kernel/ptrace.c      |  3 ++-
 arch/arm/kernel/ptrace.c        |  2 +-
 arch/arm64/kernel/ptrace.c      |  3 ++-
 arch/csky/kernel/ptrace.c       |  3 ++-
 arch/microblaze/kernel/ptrace.c |  3 ++-
 arch/mips/kernel/ptrace.c       | 11 ++++++++---
 arch/openrisc/kernel/ptrace.c   |  3 ++-
 arch/parisc/kernel/ptrace.c     |  7 +++++--
 arch/sh/kernel/ptrace_32.c      |  3 ++-
 arch/sparc/kernel/ptrace_64.c   |  3 ++-
 arch/um/kernel/ptrace.c         |  4 +++-
 arch/xtensa/kernel/ptrace.c     |  3 ++-
 include/linux/audit.h           | 11 +++++++----
 include/linux/entry-common.h    |  3 ++-
 include/uapi/linux/audit.h      |  2 ++
 kernel/audit.h                  |  2 +-
 kernel/auditfilter.c            |  2 ++
 kernel/auditsc.c                | 31 ++++++++++++++++++++-----------
 18 files changed, 67 insertions(+), 32 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 28+ messages in thread

end of thread, other threads:[~2026-08-14  8:40 UTC | newest]

Thread overview: 28+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-13 17:02 [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record Ricardo Robaina
2026-08-13 17:02 ` [PATCH 01/13] " Ricardo Robaina
2026-08-13 17:20   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 02/13] alpha: pass all six syscall args to audit_syscall_entry() Ricardo Robaina
2026-08-13 17:18   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 03/13] arm: " Ricardo Robaina
2026-08-13 17:20   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 04/13] arm64: " Ricardo Robaina
2026-08-13 17:17   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 05/13] csky: " Ricardo Robaina
2026-08-13 17:16   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 06/13] microblaze: " Ricardo Robaina
2026-08-13 17:15   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 07/13] mips: " Ricardo Robaina
2026-08-13 17:15   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 08/13] openrisc: " Ricardo Robaina
2026-08-13 17:20   ` sashiko-bot
2026-08-13 17:02 ` [PATCH 09/13] parisc: " Ricardo Robaina
2026-08-13 17:13   ` sashiko-bot
2026-08-13 17:03 ` [PATCH 10/13] sh: " Ricardo Robaina
2026-08-13 17:24   ` sashiko-bot
2026-08-13 17:03 ` [PATCH 11/13] sparc64: " Ricardo Robaina
2026-08-13 17:26   ` sashiko-bot
2026-08-13 17:03 ` [PATCH 12/13] um: " Ricardo Robaina
2026-08-13 17:19   ` sashiko-bot
2026-08-13 17:03 ` [PATCH 13/13] xtensa: " Ricardo Robaina
2026-08-13 17:23   ` sashiko-bot
2026-08-14  8:40 ` [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record Will Deacon

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.