* [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm
@ 2026-08-06 21:16 Richard Guy Briggs
2026-08-07 12:25 ` Ricardo Robaina
0 siblings, 1 reply; 3+ messages in thread
From: Richard Guy Briggs @ 2026-08-06 21:16 UTC (permalink / raw)
To: Linux-Audit Mailing List, LKML, linux-fsdevel,
Linux Kernel Audit Mailing List
Cc: Paul Moore, Eric Paris, Steve Grubb, Richard Guy Briggs,
Roman Dolgikh
Between the actual process startup (fork systemd) and the executable file
replacement (exec), systemd sets a temporary file name (executable file
name in parentheses). If an auditable system call occurs at this point,
the audit context will latch the temporary process name into the cache.
This name will not change again. The patch clears proctitle into the
audit cache when the exec call is made, allowing the new process name to
be latched.
Suggested-by: Roman Dolgikh <rmd4work@mail.ru>
Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
Link: https://github.com/linux-audit/audit-kernel/issues/170
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
---
Changelog:
v2: simplified to call single use directly before need in audit_bimprm
---
kernel/auditsc.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/auditsc.c b/kernel/auditsc.c
index 6610e667c728..c12b5dfcb279 100644
--- a/kernel/auditsc.c
+++ b/kernel/auditsc.c
@@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
{
struct audit_context *context = audit_context();
+ /* clear proctitle in audit context to allow replacement */
+ audit_proctitle_free(audit_context());
context->type = AUDIT_EXECVE;
context->execve.argc = bprm->argc;
}
--
2.43.5
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm
2026-08-06 21:16 [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm Richard Guy Briggs
@ 2026-08-07 12:25 ` Ricardo Robaina
2026-08-13 17:57 ` Richard Guy Briggs
0 siblings, 1 reply; 3+ messages in thread
From: Ricardo Robaina @ 2026-08-07 12:25 UTC (permalink / raw)
To: Richard Guy Briggs
Cc: Linux-Audit Mailing List, LKML, linux-fsdevel,
Linux Kernel Audit Mailing List, Paul Moore, Eric Paris,
Steve Grubb, Roman Dolgikh
On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <rgb@redhat.com> wrote:
>
> Between the actual process startup (fork systemd) and the executable file
> replacement (exec), systemd sets a temporary file name (executable file
> name in parentheses). If an auditable system call occurs at this point,
> the audit context will latch the temporary process name into the cache.
> This name will not change again. The patch clears proctitle into the
> audit cache when the exec call is made, allowing the new process name to
> be latched.
>
> Suggested-by: Roman Dolgikh <rmd4work@mail.ru>
> Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
> Link: https://github.com/linux-audit/audit-kernel/issues/170
> Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
> ---
> Changelog:
> v2: simplified to call single use directly before need in audit_bimprm
> ---
> kernel/auditsc.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/kernel/auditsc.c b/kernel/auditsc.c
> index 6610e667c728..c12b5dfcb279 100644
> --- a/kernel/auditsc.c
> +++ b/kernel/auditsc.c
> @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
> {
> struct audit_context *context = audit_context();
>
> + /* clear proctitle in audit context to allow replacement */
> + audit_proctitle_free(audit_context());
Since we already got the context right above, it would probably be
better to use the context var instead to avoid calling audit_context()
again.
Otherwise looks good to me.
Reviewed-by: Ricardo Robaina <rrobaina@redhat.com>
> context->type = AUDIT_EXECVE;
> context->execve.argc = bprm->argc;
> }
> --
> 2.43.5
>
>
-Ricardo
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm
2026-08-07 12:25 ` Ricardo Robaina
@ 2026-08-13 17:57 ` Richard Guy Briggs
0 siblings, 0 replies; 3+ messages in thread
From: Richard Guy Briggs @ 2026-08-13 17:57 UTC (permalink / raw)
To: Ricardo Robaina
Cc: Linux-Audit Mailing List, LKML, linux-fsdevel,
Linux Kernel Audit Mailing List, Paul Moore, Eric Paris,
Steve Grubb, Roman Dolgikh
On 2026-08-07 09:25, Ricardo Robaina wrote:
> On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <rgb@redhat.com> wrote:
> >
> > Between the actual process startup (fork systemd) and the executable file
> > replacement (exec), systemd sets a temporary file name (executable file
> > name in parentheses). If an auditable system call occurs at this point,
> > the audit context will latch the temporary process name into the cache.
> > This name will not change again. The patch clears proctitle into the
> > audit cache when the exec call is made, allowing the new process name to
> > be latched.
> >
> > Suggested-by: Roman Dolgikh <rmd4work@mail.ru>
> > Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
> > Link: https://github.com/linux-audit/audit-kernel/issues/170
> > Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
> > ---
> > Changelog:
> > v2: simplified to call single use directly before need in audit_bimprm
> > ---
> > kernel/auditsc.c | 2 ++
> > 1 file changed, 2 insertions(+)
> >
> > diff --git a/kernel/auditsc.c b/kernel/auditsc.c
> > index 6610e667c728..c12b5dfcb279 100644
> > --- a/kernel/auditsc.c
> > +++ b/kernel/auditsc.c
> > @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
> > {
> > struct audit_context *context = audit_context();
> >
> > + /* clear proctitle in audit context to allow replacement */
> > + audit_proctitle_free(audit_context());
>
> Since we already got the context right above, it would probably be
> better to use the context var instead to avoid calling audit_context()
> again.
Yup, right you are. Silly oversight.
> Otherwise looks good to me.
>
> Reviewed-by: Ricardo Robaina <rrobaina@redhat.com>
>
> > context->type = AUDIT_EXECVE;
> > context->execve.argc = bprm->argc;
> > }
> > --
> > 2.43.5
>
> -Ricardo
- RGB
--
Richard Guy Briggs <rgb@redhat.com>
Sr. S/W Engineer, Kernel Security, Base Operating Systems
Remote, Ottawa, Red Hat Canada
Upstream IRC: SunRaycer
Voice: +1.613.860 2354 SMS: +1.613.518.6570
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-13 17:58 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-06 21:16 [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm Richard Guy Briggs
2026-08-07 12:25 ` Ricardo Robaina
2026-08-13 17:57 ` Richard Guy Briggs
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox