From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-vs1-f44.google.com (mail-vs1-f44.google.com [209.85.217.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 34F5336BCE8 for ; Tue, 28 Jul 2026 16:16:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.217.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785255390; cv=none; b=mWoWG9GW5EF8lCQKcYyfhH7M9MBl3/AfoxfMHt7C+8o8VQPAaW+ZTTI3zGbCsqETvRM7MMrdz4/sw6xv/7mFWUNw9bNHi5CXoATVZm0WP+6KIzPxoJsIaYds9wo+E+wzsY5X3Zgdn177ZdMPB8YYXGWmsdExAW9hqYnoZouQhM0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785255390; c=relaxed/simple; bh=zbP0fgi+EApB+uBYo7yptEDQz6XO8DHNjqcRXnDFGI8=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=pHsIbFRJMXc1yRBC2IpDs878pN1vxdp1bEAm9ziffRza6A4mMO583lzMt/oRVwWINhDFjYbhutDy+KPLAh5F/qVl4h0Lb7fkOiNcuRAHxsYWpV25aJs+273nLfsRU9S9p5WZi07OyANi45g+qwEjsvimgIlkaWeDAWaLMr4p5LU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=MLrO+Sc4; arc=none smtp.client-ip=209.85.217.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="MLrO+Sc4" Received: by mail-vs1-f44.google.com with SMTP id ada2fe7eead31-73b909fbb6bso2813943137.2 for ; Tue, 28 Jul 2026 09:16:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1785255387; x=1785860187; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cAriX3tLCmrnUO4qSHhwDGkR5q4S1pPXvajnZr56PhA=; b=MLrO+Sc4b6q1HMMDqe8zweEY+eTufkd72mEHrcIeunJYiD+DD8V3OG6GtVPpqOETgf 5eiXG39R6K6hoE7+QJXkI2Luw5UzPtDYiaB8Gs17bACYCsCG8nhymMPxlcfrulcdKfap QLxp8M7Hzc07VUZqFr6zWw8gZyP9K0PJjQCoBwIwZULxzOeI3tZyALg8nhbKRV3nZzFx vHUYM7XA0Mi46VMkSq6YTUr8ySBzQxhvs1298n0Fc+6amab5jL3t5JlPUT9+pa5Dmivm 29uFdxdKQ6eYJO+r6HPiqe6gD/VCbBJQ3FZk56Bm86uI6jWgJJXbAbLhRKFNkr+HpSB2 ntLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785255387; x=1785860187; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cAriX3tLCmrnUO4qSHhwDGkR5q4S1pPXvajnZr56PhA=; b=KywDCeJfpc2H/rw5wfR1aYV1PyzOw3nKLob1ei5fgmpKtAGycco2fIWI7+KmPndSzR we95dQc9YjFqlqS+N8sPba5WYwhguzSJ7QNteAtIX4pW/LTaedhPmMnnglZ3jsrbJf1P ltREoIpWY1Awgd/5NremhPi4iTFz0LlpJhPQNhsKZwSV0RNSc0xxbXJfNuY8HBQeJYWn iKOTY9f4oT0LXBj/RdE00GlXYZX563XsLHqwLtxjo13/YUXFn2J0gXv+iJLndwqWS24g Vd7PaNJ1wqRkGIlaNjf4jaMCj0ud438zzQ962bEOkoXoT31wPcckguv926gMhbc5HTcV dvxw== X-Forwarded-Encrypted: i=1; AHgh+RqOPiTGc6slpRG6BUw6xhG7HDYDG1rFYq0xezqi/RMZkaxiSwk3vqxs4dFMGUAxO98MuazR2855Hd8/yGU=@vger.kernel.org X-Gm-Message-State: AOJu0YzYOGNtpXPGXTK9SzIXBbGx2mclXRSlUrHtVRNmf57f0OvskUCJ CfauTYHaajcJ662lLpWYURKMEK/O+Qc3xDsct+oEi/rhC1uE4qwhGNbxSWNJ6b8ILg== X-Gm-Gg: AR+sD12lQq7I36rxsABWrc/K8WANoZCTnzxY/dbPeGpAOsCMKadoYTbSdBYOtub1jRm RRs6InzTZzJPdsgka11wwPAIaxwNiAq98A2C+ysg7FLr4bfVjMjesN1/OZavKvHYMsgkmzt/wDn lXn/CflUIfpnFyeB6Qu2B1s9V88bQn6hMCTYIE8/eJE05r1JSh5mo3T9M0b1tLszYWf4vb/dqhq ofnEY8WDdiY63f/1Rz9Kzw8KKVpIZIwcsLaQCk2cEnUvhhi0hFDONM7jT3/tl8KoqKj9TEavMD2 qMTenx2zkTmDAKLicjowciUR0qu2/S5ZZWXkLdiNpN+1OxGrqHFExF1HFNZK+4za8CK8XphMsaj y3TKbUrcwzhzdAEq/+cUhDfjs5gGYcEaLN08ZYuysaCyEm6fuNPHJX4i/kHTcH+JxnFMXH+Egwh I4iwyKad9BcwDhJywZaaat1WlXHIOc6VIbp2oDhZ/7B0rGH9U= X-Received: by 2002:a05:6102:942:b0:737:ba2e:8a26 with SMTP id ada2fe7eead31-754a2dcd8f7mr1579232137.27.1785255386692; Tue, 28 Jul 2026 09:16:26 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-9081dc44d0fsm2424756d6.6.2026.07.28.09.16.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 09:16:25 -0700 (PDT) Date: Tue, 28 Jul 2026 12:16:24 -0400 Message-ID: <2f53e3c8ee57824f1c741f76021eb2ce@paul-moore.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260727_1648/pstg-lib:20260728_1147/pstg-pwork:20260727_1648 From: Paul Moore To: Richard Guy Briggs , Linux-Audit Mailing List , LKML , linux-fsdevel@vger.kernel.org, Linux Kernel Audit Mailing List Cc: Eric Paris , Steve Grubb , Richard Guy Briggs Subject: Re: [PATCH v1] audit: free proctitle in context so it can be set by fork References: In-Reply-To: On Jul 26, 2026 Richard Guy Briggs wrote: > > Original title: fixes clean proctitle in audit context on exec call Please don't add stuff like that to the description, it's not particularly helpful by itself. If you want to link this patch to something outside of the git log, use the 'Link:' tag. > Between the actual process startup (fork systemd) and the executable file > replacement (exec), systemd sets a temporary file name (executable file > name in parentheses). If an auditable system call occurs at this point, > the audit context will latch the temporary process name into the cache. > This name will not change again. The patch clears proctitle into the > audit cache when the exec call is made, allowing the new process name to > be latched. > > Suggested by Roman Dolgikh https://github.com/rmd4ctf 2025-06-11 Considering that Roman lists an email on his public GH profile, it would be better to use a traditional "Suggested-by:" tag, for example: Suggested-by: Roman Dolgikh > Link: https://github.com/linux-audit/audit-kernel/issues/170. No trailing period please. > Signed-off-by: Richard Guy Briggs > Acked-by: Christian Brauner > --- > fs/exec.c | 2 ++ > include/linux/audit.h | 9 +++++++++ > kernel/auditsc.c | 4 ++-- > 3 files changed, 13 insertions(+), 2 deletions(-) > > diff --git a/fs/exec.c b/fs/exec.c > index b92fe7db176c..bd51489dec23 100644 > --- a/fs/exec.c > +++ b/fs/exec.c > @@ -1744,6 +1744,8 @@ static int exec_binprm(struct linux_binprm *bprm) > fput(exec); > } > > + /* clear proctitle in audit context to allow replacement */ > + audit_proctitle_free(audit_context()); > audit_bprm(bprm); Since this is the only place where audit_bprm() is called, is there any reason why you simply didn't just move the free into __audit_bprm()? Doing so should shrink this patch considerably and would keep the audit overhead to just a single !audit_dummy_context() check as it is now. -- paul-moore.com