From: Paul Moore <paul@paul-moore.com>
To: "Christian Göttsche" <cgoettsche@seltendoof.de>, audit@vger.kernel.org
Cc: "Eric Paris" <eparis@redhat.com>,
"Christian Göttsche" <cgzones@googlemail.com>
Subject: Re: [PATCH RFC 2/4] audit: compact name entries and context fields
Date: Mon, 28 Sep 2026 18:10:51 -0400 [thread overview]
Message-ID: <cf63164d7934f3e0c2ab5f4b5c00e494@paul-moore.com> (raw)
In-Reply-To: <20260917143948.106603-2-cgoettsche@seltendoof.de>
On Sep 17, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
>
> Group aligned name fields and small scalar fields to remove padding. Keep
> file capabilities last so they do not separate inode and pathname metadata.
> Store the per-name file capability revision in s16: it must represent both
> the eight-bit on-disk revision and the -1 AUDIT_INODE_NOEVAL sentinel. Keep
> the existing formatter and its unknown-capability output unchanged.
>
> Move name_count beside return_valid to remove two alignment holes, and
> place personality before the task credential scalars. Preserve the first
> int dummy member required by audit_dummy_context(), all five embedded name
> slots, and the existing allocation and reference lifetimes.
>
> On x86_64 with SELinux this reduces audit_context from 928 to 880 bytes,
> leaving room for descriptor paths while staying below 1 KiB. On the tested
> arm64 configuration without property-bearing LSMs it falls to 872 bytes.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> ---
> kernel/audit.h | 17 ++++++++---------
> 1 file changed, 8 insertions(+), 9 deletions(-)
>
> diff --git a/kernel/audit.h b/kernel/audit.h
> index 7640d2c0fba4..bd798f8553a0 100644
> --- a/kernel/audit.h
> +++ b/kernel/audit.h
> @@ -76,18 +76,16 @@ struct audit_names {
> struct list_head list; /* audit_context->names_list */
>
> struct filename *name;
> - int name_len; /* number of chars to log */
> - bool hidden; /* don't log this record */
> -
> u64 ino;
> + struct lsm_prop oprop;
> dev_t dev;
> - umode_t mode;
> kuid_t uid;
> kgid_t gid;
> dev_t rdev;
> - struct lsm_prop oprop;
> - struct audit_file_caps fcap;
> - unsigned int fcap_ver;
> + int name_len; /* number of chars to log */
> + s16 fcap_ver; /* 8-bit revision, or -1 for NOEVAL */
Should we also change the fcap_ver in audit_aux_data_bprm_fcaps?
> + umode_t mode;
> + bool hidden; /* don't log this record */
> unsigned char type; /* record type */
> /*
> * This was an allocated audit_names and not from the array of
> @@ -95,6 +93,7 @@ struct audit_names {
> * should be freed on syscall exit.
> */
> bool should_free;
> + struct audit_file_caps fcap;
> };
I understand why you moved the fields as you did, but is there any way
we can keep name adjacent to name_len and fcap adjacent to fcap_ver?
Splitting them makes the structure layout awkward to read.
You would need to check that this is safe, but if it helps we could
probably change name_len to a shorter type as PATH_MAX is only 4k and
that limit is part of the UAPI so it isn't easily changed.
> struct audit_proctitle {
> @@ -124,6 +123,7 @@ struct audit_context {
> long return_code;/* syscall return code */
> u64 prio;
> int return_valid; /* return code is valid */
> + int name_count; /* total records in names_list */
I think it would look better to move this below the comment that is
directly below it so it remains adjacent to audit_names. This shouldn't
affect the struct padding/packing.
> /*
> * The names_list is the list of all audit_names collected during this
> * syscall. The first AUDIT_NAMES entries in the names_list will
> @@ -133,7 +133,6 @@ struct audit_context {
> * by running the names_list.
> */
> struct audit_names preallocated_names[AUDIT_NAMES];
> - int name_count; /* total records in names_list */
> struct list_head names_list; /* struct audit_names->list anchor */
> char *filterkey; /* key for rule that triggered record */
> struct path pwd;
> @@ -142,10 +141,10 @@ struct audit_context {
> struct sockaddr_storage *sockaddr;
> size_t sockaddr_len;
> /* Save things to print about task_struct */
> + unsigned long personality;
> pid_t ppid;
> kuid_t uid, euid, suid, fsuid;
> kgid_t gid, egid, sgid, fsgid;
> - unsigned long personality;
> int arch;
>
> pid_t target_pid;
> --
> 2.55.0
--
paul-moore.com
next prev parent reply other threads:[~2026-09-28 22:10 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 14:39 [RFC PATCH 1/4] audit: separate file and process capability storage Christian Göttsche
2026-09-17 14:39 ` [RFC PATCH 2/4] audit: compact name entries and context fields Christian Göttsche
2026-09-17 14:49 ` sashiko-bot
2026-09-28 22:10 ` Paul Moore [this message]
2026-09-17 14:39 ` [RFC PATCH 3/4] audit: return the collected inode entry from a private helper Christian Göttsche
2026-09-17 14:45 ` sashiko-bot
2026-09-28 22:10 ` [PATCH RFC " Paul Moore
2026-09-17 14:39 ` [RFC PATCH 4/4] audit: retain file paths for descriptor PATH records Christian Göttsche
2026-09-17 14:58 ` sashiko-bot
2026-09-28 22:10 ` [PATCH RFC " Paul Moore
2026-09-17 14:50 ` [RFC PATCH 1/4] audit: separate file and process capability storage sashiko-bot
2026-09-28 22:10 ` [PATCH RFC " Paul Moore
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cf63164d7934f3e0c2ab5f4b5c00e494@paul-moore.com \
--to=paul@paul-moore.com \
--cc=audit@vger.kernel.org \
--cc=cgoettsche@seltendoof.de \
--cc=cgzones@googlemail.com \
--cc=eparis@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox