Audit system development
 help / color / mirror / Atom feed
From: Paul Moore <paul@paul-moore.com>
To: "Christian Göttsche" <cgoettsche@seltendoof.de>, audit@vger.kernel.org
Cc: "Eric Paris" <eparis@redhat.com>,
	"Christian Göttsche" <cgzones@googlemail.com>
Subject: Re: [PATCH RFC 2/4] audit: compact name entries and context fields
Date: Mon, 28 Sep 2026 18:10:51 -0400	[thread overview]
Message-ID: <cf63164d7934f3e0c2ab5f4b5c00e494@paul-moore.com> (raw)
In-Reply-To: <20260917143948.106603-2-cgoettsche@seltendoof.de>

On Sep 17, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
> 
> Group aligned name fields and small scalar fields to remove padding. Keep
> file capabilities last so they do not separate inode and pathname metadata.
> Store the per-name file capability revision in s16: it must represent both
> the eight-bit on-disk revision and the -1 AUDIT_INODE_NOEVAL sentinel. Keep
> the existing formatter and its unknown-capability output unchanged.
> 
> Move name_count beside return_valid to remove two alignment holes, and
> place personality before the task credential scalars. Preserve the first
> int dummy member required by audit_dummy_context(), all five embedded name
> slots, and the existing allocation and reference lifetimes.
> 
> On x86_64 with SELinux this reduces audit_context from 928 to 880 bytes,
> leaving room for descriptor paths while staying below 1 KiB. On the tested
> arm64 configuration without property-bearing LSMs it falls to 872 bytes.
> 
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> ---
>  kernel/audit.h | 17 ++++++++---------
>  1 file changed, 8 insertions(+), 9 deletions(-)
> 
> diff --git a/kernel/audit.h b/kernel/audit.h
> index 7640d2c0fba4..bd798f8553a0 100644
> --- a/kernel/audit.h
> +++ b/kernel/audit.h
> @@ -76,18 +76,16 @@ struct audit_names {
>  	struct list_head	list;		/* audit_context->names_list */
>  
>  	struct filename		*name;
> -	int			name_len;	/* number of chars to log */
> -	bool			hidden;		/* don't log this record */
> -
>  	u64			ino;
> +	struct lsm_prop		oprop;
>  	dev_t			dev;
> -	umode_t			mode;
>  	kuid_t			uid;
>  	kgid_t			gid;
>  	dev_t			rdev;
> -	struct lsm_prop		oprop;
> -	struct audit_file_caps	fcap;
> -	unsigned int		fcap_ver;
> +	int			name_len;	/* number of chars to log */
> +	s16			fcap_ver;	/* 8-bit revision, or -1 for NOEVAL */

Should we also change the fcap_ver in audit_aux_data_bprm_fcaps?

> +	umode_t			mode;
> +	bool			hidden;		/* don't log this record */
>  	unsigned char		type;		/* record type */
>  	/*
>  	 * This was an allocated audit_names and not from the array of
> @@ -95,6 +93,7 @@ struct audit_names {
>  	 * should be freed on syscall exit.
>  	 */
>  	bool			should_free;
> +	struct audit_file_caps	fcap;
>  };

I understand why you moved the fields as you did, but is there any way
we can keep name adjacent to name_len and fcap adjacent to fcap_ver?
Splitting them makes the structure layout awkward to read.

You would need to check that this is safe, but if it helps we could
probably change name_len to a shorter type as PATH_MAX is only 4k and
that limit is part of the UAPI so it isn't easily changed.

>  struct audit_proctitle {
> @@ -124,6 +123,7 @@ struct audit_context {
>  	long		    return_code;/* syscall return code */
>  	u64		    prio;
>  	int		    return_valid; /* return code is valid */
> +	int		    name_count; /* total records in names_list */

I think it would look better to move this below the comment that is
directly below it so it remains adjacent to audit_names.  This shouldn't
affect the struct padding/packing.

>  	/*
>  	 * The names_list is the list of all audit_names collected during this
>  	 * syscall.  The first AUDIT_NAMES entries in the names_list will
> @@ -133,7 +133,6 @@ struct audit_context {
>  	 * by running the names_list.
>  	 */
>  	struct audit_names  preallocated_names[AUDIT_NAMES];
> -	int		    name_count; /* total records in names_list */
>  	struct list_head    names_list;	/* struct audit_names->list anchor */
>  	char		    *filterkey;	/* key for rule that triggered record */
>  	struct path	    pwd;
> @@ -142,10 +141,10 @@ struct audit_context {
>  	struct sockaddr_storage *sockaddr;
>  	size_t sockaddr_len;
>  	/* Save things to print about task_struct */
> +	unsigned long	    personality;
>  	pid_t		    ppid;
>  	kuid_t		    uid, euid, suid, fsuid;
>  	kgid_t		    gid, egid, sgid, fsgid;
> -	unsigned long	    personality;
>  	int		    arch;
>  
>  	pid_t		    target_pid;
> -- 
> 2.55.0

--
paul-moore.com

  parent reply	other threads:[~2026-09-28 22:10 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 14:39 [RFC PATCH 1/4] audit: separate file and process capability storage Christian Göttsche
2026-09-17 14:39 ` [RFC PATCH 2/4] audit: compact name entries and context fields Christian Göttsche
2026-09-17 14:49   ` sashiko-bot
2026-09-28 22:10   ` Paul Moore [this message]
2026-09-17 14:39 ` [RFC PATCH 3/4] audit: return the collected inode entry from a private helper Christian Göttsche
2026-09-17 14:45   ` sashiko-bot
2026-09-28 22:10   ` [PATCH RFC " Paul Moore
2026-09-17 14:39 ` [RFC PATCH 4/4] audit: retain file paths for descriptor PATH records Christian Göttsche
2026-09-17 14:58   ` sashiko-bot
2026-09-28 22:10   ` [PATCH RFC " Paul Moore
2026-09-17 14:50 ` [RFC PATCH 1/4] audit: separate file and process capability storage sashiko-bot
2026-09-28 22:10 ` [PATCH RFC " Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cf63164d7934f3e0c2ab5f4b5c00e494@paul-moore.com \
    --to=paul@paul-moore.com \
    --cc=audit@vger.kernel.org \
    --cc=cgoettsche@seltendoof.de \
    --cc=cgzones@googlemail.com \
    --cc=eparis@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox