Audit system development
 help / color / mirror / Atom feed
* [RFC PATCH 1/4] audit: separate file and process capability storage
@ 2026-09-17 14:39 Christian Göttsche
  2026-09-17 14:39 ` [RFC PATCH 2/4] audit: compact name entries and context fields Christian Göttsche
                   ` (4 more replies)
  0 siblings, 5 replies; 12+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:39 UTC (permalink / raw)
  To: audit; +Cc: Paul Moore, Eric Paris, Christian Göttsche

From: Christian Göttsche <cgzones@googlemail.com>

File capabilities need permitted and inheritable sets, an effective flag,
and a root UID. Process capabilities need four full capability sets but
neither a file effective flag nor a root UID. Give file capabilities their
own type instead of storing both representations in audit_cap_data.

This reduces each preallocated audit_names entry by 16 bytes on the tested
64-bit configurations, saving 80 bytes per audit context. The BPRM
capability auxiliary object also shrinks from 144 to 112 bytes. Retain all
logged fields, including file root IDs and process ambient capabilities;
record formats and collection behavior are unchanged.

Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
 kernel/audit.h   | 15 +++++++++------
 kernel/auditsc.c |  2 +-
 2 files changed, 10 insertions(+), 7 deletions(-)

diff --git a/kernel/audit.h b/kernel/audit.h
index 3176da464843..7640d2c0fba4 100644
--- a/kernel/audit.h
+++ b/kernel/audit.h
@@ -53,15 +53,18 @@ struct audit_entry {
 	struct audit_krule	rule;
 };
 
+struct audit_file_caps {
+	kernel_cap_t		permitted;
+	kernel_cap_t		inheritable;
+	unsigned int		fE;		/* effective bit of file cap */
+	kuid_t			rootid;
+};
+
 struct audit_cap_data {
 	kernel_cap_t		permitted;
 	kernel_cap_t		inheritable;
-	union {
-		unsigned int	fE;		/* effective bit of file cap */
-		kernel_cap_t	effective;	/* effective set of process */
-	};
+	kernel_cap_t		effective;
 	kernel_cap_t		ambient;
-	kuid_t			rootid;
 };
 
 /* When fs/namei.c:getname() is called, we store the pointer in name and bump
@@ -83,7 +86,7 @@ struct audit_names {
 	kgid_t			gid;
 	dev_t			rdev;
 	struct lsm_prop		oprop;
-	struct audit_cap_data	fcap;
+	struct audit_file_caps	fcap;
 	unsigned int		fcap_ver;
 	unsigned char		type;		/* record type */
 	/*
diff --git a/kernel/auditsc.c b/kernel/auditsc.c
index ee7e53d2cd52..464736499c83 100644
--- a/kernel/auditsc.c
+++ b/kernel/auditsc.c
@@ -107,7 +107,7 @@ struct audit_aux_data_pids {
 
 struct audit_aux_data_bprm_fcaps {
 	struct audit_aux_data	d;
-	struct audit_cap_data	fcap;
+	struct audit_file_caps	fcap;
 	unsigned int		fcap_ver;
 	struct audit_cap_data	old_pcap;
 	struct audit_cap_data	new_pcap;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-28 22:10 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 14:39 [RFC PATCH 1/4] audit: separate file and process capability storage Christian Göttsche
2026-09-17 14:39 ` [RFC PATCH 2/4] audit: compact name entries and context fields Christian Göttsche
2026-09-17 14:49   ` sashiko-bot
2026-09-28 22:10   ` [PATCH RFC " Paul Moore
2026-09-17 14:39 ` [RFC PATCH 3/4] audit: return the collected inode entry from a private helper Christian Göttsche
2026-09-17 14:45   ` sashiko-bot
2026-09-28 22:10   ` [PATCH RFC " Paul Moore
2026-09-17 14:39 ` [RFC PATCH 4/4] audit: retain file paths for descriptor PATH records Christian Göttsche
2026-09-17 14:58   ` sashiko-bot
2026-09-28 22:10   ` [PATCH RFC " Paul Moore
2026-09-17 14:50 ` [RFC PATCH 1/4] audit: separate file and process capability storage sashiko-bot
2026-09-28 22:10 ` [PATCH RFC " Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox