From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f52.google.com (mail-qv1-f52.google.com [209.85.219.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C002E4749C1 for ; Tue, 28 Jul 2026 20:35:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785270925; cv=none; b=qynOyxzsdBe4Ina+tB/zpNZ+1MuQn3who3N4gQQNfNI9xVpkOdZkGr7qpJa3/gM2KJNjbB39PRmNubhbVC7i5yJr862QyAU/hItfjH4tzRZXeRc7+880CeKmm8FiUtEgpHxS9fBXuWDsln1bkrLSwAyAy7dG10Jnh2K6r1Gtguc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785270925; c=relaxed/simple; bh=U+lLKCY0/w93eWsjz8487mJt+6NDu0yjnjNJQWdKrhI=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=HSKnhU/VOraRLtFIa160H8aGb6VArjQcJqQgR4N1+9jw+0snkKuMGEqrEuMLy2LX9Mw0eYaWchjnD7b/HXnmdt5G0WV7b05o4GdA+D+UwdR2bB1Hs9lcUn7/KiVci2AO9n/jMeu0Df2aczxmGx+kl0xIFDXPhGcp0zrS1XIDTsY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=YGh+shex; arc=none smtp.client-ip=209.85.219.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="YGh+shex" Received: by mail-qv1-f52.google.com with SMTP id 6a1803df08f44-8edda5d56a5so2212866d6.3 for ; Tue, 28 Jul 2026 13:35:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1785270922; x=1785875722; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iSEcN1E6s5lwXI7JRu7ScxVibRaffsPscjiA9BZ0LTc=; b=YGh+shexvq1CjsefBmoEodQLeHvME5lTkgU0YCWsNq7PWIDcEmaXJjHaJtGJ29rxul ExjzmXmavxwZJefklb8xwbwqiiYHH2s4hPUdEe1m3/adqvx7lFeTXhrbf5zSbI3pKyH8 v5PciBZaXv2dPRy09RM5utyVXy8t9eBUPzADSJ5lw0F6d8ElL56Xm3fZQ3GdxOgUqaF7 +srYLjC1tRSGMyDoAA6mi/xYnHgwlsXBT2dvhCWyu/5VyExve5AYhLwqaAzKd476zPc7 EKUW17z8In+Cy/vqc/8zQLAdTBBFjgqYJa4KW1xUL7idGD6tTyTv1JkQe7uuPAPyAm1u QoSQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785270922; x=1785875722; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=iSEcN1E6s5lwXI7JRu7ScxVibRaffsPscjiA9BZ0LTc=; b=Wk/9Ny55A8YEIjKEv04cErKPis0cPxrTp/fVZZj5bDz03YG2Pds4ME5RD0wP1zEhbp tJqNdbIeDVy1G0W3Suujo+OO5FvFv+atV3Vxo1WWh7wgqV4BdRvWGk+K1soELsKK0pAU 7/UwCF0B9blDZ3kJPn2SvF58OTA5HSKRegdUdMP73KafeHN2hu2WL+t2Sg7myQGwtoXb MoDkfeorxtlDw1LFKOSe8yXrj5gq4DKvv228FyGvEQL6EksFUNKm7u9ViUYonS8eyXNx 1/qPgI/QjSSeGmv4GdK2gvE6oWZWAn7g6O3rXKtwlg5i/AIYbVY/Pl++UnG1CwFYExLa pZyg== X-Forwarded-Encrypted: i=1; AHgh+RqrfAXX8TVM7UTYGkS5vXs6zt1Yde+SkBdGuR/cCTwNeJ3f1KKlvpQw560qGnQ+/uME5kKtqtx0WniS4oc=@vger.kernel.org X-Gm-Message-State: AOJu0Yyr4V0NlCJIPx8iniJguPuv8RW3E5PvAZV7pGDOOiyDGszecS96 zZsRznol5IoDqav4A00YWQewZoJZG0fiHsu09FQJM/4XqqBbudScLXsT5haEy3M6Mg== X-Gm-Gg: AR+sD13zHdE31bKr+ok8MvVIZxC1FII0BtatnwAqb/VIa3c+KVOM4dR6Ez5ppICXmuh 2K0U7azmy5IQld/rkjgfvDfwUtDWRysv22r1oRCPsSdgL3s/ZUKu3qgQdTLipCWtft2bzm7bGBK BzQMCiZdksVzLvcwJX3QHBNNGTPz6WCv+g95eB6B3IUXhZqGvQw2xWlso6yG+4pDm2MAxrDijpc p8W3iSOJob+O4Ojriw58yRQbU79Wp8Hi9ssLL299SMfZwUG2zhXKD4VkbhZ3tWQYBOtfDJGWdXk 9SIzUL9MOrFaa62T5E89SKNLYycibUBbDkkK+a+zmh+MuXWO87FMyR7v5k45FhnZBQRPqvr3vSb nUJYeCdb3g1p3Uc3Hs3my9tFl0CVv32EacccNhKi+r0TBWqJAReXbIR8FSxpgrLUgMzh1aE3tOL H0d8ny6Qn/oHiatJ+aUNKItqxLZQUMrhq/aRYQbZn+cgUerADDjl4cEjfASVrqD8kztnUvQcbRD JkOmpN2J7zCcHUZ148boowD+LoFvd0Fww== X-Received: by 2002:a05:6214:5a01:b0:906:2b80:4684 with SMTP id 6a1803df08f44-90816fbbd62mr45289446d6.3.1785270922456; Tue, 28 Jul 2026 13:35:22 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-9081dc44d0fsm7433266d6.6.2026.07.28.13.35.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 13:35:21 -0700 (PDT) Date: Tue, 28 Jul 2026 16:35:20 -0400 Message-ID: <4fad20e4737ff546ce0a822d9522adac@paul-moore.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260727_1648/pstg-lib:20260728_1147/pstg-pwork:20260727_1648 From: Paul Moore To: Ricardo Robaina , audit@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Cc: eparis@redhat.com, viro@zeniv.linux.org.uk, brauner@kernel.org, jack@suse.cz, sgrubb@redhat.com, rbriggs@redhat.com, Ricardo Robaina Subject: Re: [PATCH v2] audit: add FSCONFIG auxiliary record to log filesystem configuration References: <20260727173710.964626-1-rrobaina@redhat.com> In-Reply-To: <20260727173710.964626-1-rrobaina@redhat.com> On Jul 27, 2026 Ricardo Robaina wrote: > > Modern mount tools (util-linux >= 2.39.1) use the new mount API > (fsopen, fsconfig, fsmount, move_mount) instead of the legacy mount(2) > syscall. The generic SYSCALL audit record logs the fsconfig syscall but > does not capture the configuration parameters, creating an audit gap for > critical mount information such as the device being mounted. > > Add an FSCONFIG auxiliary record that logs the command type, parameter > name (key), parameter value, and aux parameter passed to fsconfig(2). > > ---- > type=SYSCALL : syscall=fsconfig ... a1=FSCONFIG_SET_STRING ... > type=FSCONFIG : fs_cmd=1 fs_key=source fs_val="tmpfs" fs_aux=0 > ---- > type=SYSCALL : syscall=fsconfig ... a1=FSCONFIG_CMD_CREATE ... > type=FSCONFIG : fs_cmd=6 fs_key=(null) fs_val=(null) fs_aux=0 > ---- > type=SYSCALL : syscall=fsconfig ... a1=FSCONFIG_SET_BINARY ... > type=FSCONFIG : fs_cmd=2 fs_key=hidepid fs_val="" fs_aux=4 > > Link: https://github.com/linux-audit/audit-kernel/issues/153 > Acked-by: Christian Brauner > Signed-off-by: Ricardo Robaina > --- > Changes in v2: > - Fixed null-check for fs_key field. > - Clarified trimmed SYSCALL output in commit message examples. > > fs/fsopen.c | 7 +++++++ > include/linux/audit.h | 13 +++++++++++++ > include/uapi/linux/audit.h | 1 + > kernel/auditsc.c | 27 +++++++++++++++++++++++++++ > 4 files changed, 48 insertions(+) > > diff --git a/fs/fsopen.c b/fs/fsopen.c > index ae19e5136598..9b3c02f59df4 100644 > --- a/fs/fsopen.c > +++ b/fs/fsopen.c > @@ -15,6 +15,7 @@ > #include > #include > #include > +#include > #include "internal.h" > #include "mount.h" > > @@ -357,6 +358,7 @@ SYSCALL_DEFINE5(fsconfig, > struct fs_context *fc; > int ret; > int lookup_flags = 0; > + const char *value_str = NULL; > > struct fs_parameter param = { > .type = fs_value_is_undefined, > @@ -423,6 +425,7 @@ SYSCALL_DEFINE5(fsconfig, > goto out_key; > } > param.size = strlen(param.string); > + value_str = param.string; > break; > case FSCONFIG_SET_BINARY: > param.type = fs_value_is_blob; > @@ -432,6 +435,7 @@ SYSCALL_DEFINE5(fsconfig, > ret = PTR_ERR(param.blob); > goto out_key; > } > + value_str = ""; Is there a reason why we're not logging the binary data? We might want to impose a size limit to truncate the logged data (although we have provisions to log rather large binary chunks), but I don't see a reason why we couldn't log the binary data as a hex string. > break; > case FSCONFIG_SET_PATH_EMPTY: > lookup_flags = LOOKUP_EMPTY; > @@ -445,6 +449,7 @@ SYSCALL_DEFINE5(fsconfig, > } > param.dirfd = aux; > param.size = strlen(param.name->name); > + value_str = param.name->name; > break; > case FSCONFIG_SET_FD: > param.type = fs_value_is_file; > @@ -458,6 +463,8 @@ SYSCALL_DEFINE5(fsconfig, > break; > } > > + audit_log_fsconfig(cmd, param.key, value_str, aux); > + > ret = mutex_lock_interruptible(&fc->uapi_mutex); > if (ret == 0) { > ret = vfs_fsconfig_locked(fc, cmd, ¶m); ... > diff --git a/kernel/auditsc.c b/kernel/auditsc.c > index 6610e667c728..fefc5c5dd4aa 100644 > --- a/kernel/auditsc.c > +++ b/kernel/auditsc.c > @@ -2882,6 +2882,33 @@ void __audit_log_nfcfg(const char *name, u8 af, unsigned int nentries, > } > EXPORT_SYMBOL_GPL(__audit_log_nfcfg); > > +void __audit_log_fsconfig(unsigned int cmd, const char *key, > + const char *value, int aux) > +{ > + struct audit_buffer *ab; > + > + ab = audit_log_start(audit_context(), GFP_KERNEL, AUDIT_FSCONFIG); > + if (!ab) > + return; > + > + audit_log_format(ab, "fs_cmd=%u", cmd); > + audit_log_format(ab, " fs_key="); Calling into audit_log_format() is expensive due to the string processing, we should combine this into a single audit_log_format() call: audit_log_format(ab, "fs_cmd=%u fs_key=", cmd); > + if (key) > + audit_log_untrustedstring(ab, key); > + else > + audit_log_format(ab, "(null)"); > + > + audit_log_format(ab, " fs_val="); > + if (value) > + audit_log_untrustedstring(ab, value); > + else > + audit_log_format(ab, "(null)"); > + > + audit_log_format(ab, " fs_aux=%d", aux); > + > + audit_log_end(ab); > +} > + > static void audit_log_task(struct audit_buffer *ab) > { > kuid_t auid, uid; > -- > 2.53.0 -- paul-moore.com