From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f177.google.com (mail-qk1-f177.google.com [209.85.222.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F0942E62AC for ; Wed, 12 Aug 2026 20:46:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786567619; cv=none; b=hBkdXcihX05xSJXFqrUB8VDheZ9i3JUyzIKFBiOXrZL/4/bXKe4te5OcUzmFjYaRR4ijKXdSS7CTYJRSSJ/6PSjcx1HT2hpik5LeqYy1PwBEAJJHzYfUFy8Aoji+4OuadaNf40ffxuMUUhQEcf5G+t3yPqYY3fQoZnIu3orp65A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786567619; c=relaxed/simple; bh=4I/32K7J6mxO5dI6LSD3V4ov9JkZ/eYl//UrtEaxHF8=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=UXqIJ95wPPzzcMazPnunq1x7p6XCuRz5shQf2kXXRo0rZa4UB0x19o3dBqa+u35hdIJqJSiK3hXjNXVKrgKF38mJSB1KBZVPfOJuZv8nk9qNIzAaq9dl+VQQvIV9qj+J4oe7yh6JLfZhnsMWCl1W6TgAHPgYRZ/rmcVc6M7Ikv0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=ZzPDPIbA; arc=none smtp.client-ip=209.85.222.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="ZzPDPIbA" Received: by mail-qk1-f177.google.com with SMTP id af79cd13be357-92ed3993c1eso89013285a.1 for ; Wed, 12 Aug 2026 13:46:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1786567615; x=1787172415; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TRATdCyioF/pQhvH8lNkn9inChCQPeW2cLYdQioNcfM=; b=ZzPDPIbA1Wmp7ip52/urB7EBnboCiYx09XVmLk1OpKYWRf1/q7ZwHhwt9DxPO5KXJH OTWxP9/1sqJ/tWiEUKfby8XjYFd03MAMZyw9LOROGlzhqTwmxmztXkIp/4nVHWd/SDH5 W5CPyFdLLjL6VQRqk1I4LsVlFt96Ud3le7lXqC/ktQmcZ4MmfTHdPy2TemyJYq4/lg4a 1Rquo1WcraWWGJRixaTsEj/V5n3ic1LXhrSyWUep4Py1RC/79+BDu3eg+vu78R2+BrNz ImE9Y2keX8e0NFVXb6dWf2jQ9W4su5X/wTW7KWxIrwi5b7Dzw//yOM+ozNDRYuKx/Vr2 Pfig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786567615; x=1787172415; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TRATdCyioF/pQhvH8lNkn9inChCQPeW2cLYdQioNcfM=; b=mfkno5Co9+JDynnwf4le2R5iy52b66pVowSxVsshBrfXPeM4GKn9osOI2oSGCwpij2 +eEel8GGCDWcrS6XDOaRJjOiGuTQa66YEfKonTBpwi/x31+tek52cOKmXRpIsJNGdWQD tX6LoPlN+mT+D0IH6QzLk5hx3YFjAWnYOTg11O7S2VDBnfD8iaVrwfNPpsxAobn9DZHM 8j4YXkYvHEFD4RCY8Zw1E3BoJUio1bkPLkA+xey4jz5wbiopq4C1WjG0dlIfz5LCuoVf F1Ttr6jeLQ6JAiUaiD5RA1ChIbkGHbMrG1GSAn6dYWEzIH33KJnGi6i0RThnMIHmOmOv 76Fw== X-Forwarded-Encrypted: i=1; AHgh+RpwHuvl/WmUQTzcBRoM/RLbN99J2t41t7c4nDohm5WldI+h5JcoUfD9O/Qh5K26Yu97TFgziMV7VlmqSts=@vger.kernel.org X-Gm-Message-State: AOJu0YwpXpWtQCu+DwDnyiHNnv4FYdmRaXb5EIkyElXp56DeFoG8wtwQ BRENw7ClOEF89D7tcn3m1DV9J4EcXxG0HSh+AHzjNw5EYJUkcNKxrGYASzspjZE+YRpnub2vYt/ yGLO0bw== X-Gm-Gg: AR+sD10ROJCkX9zxLV23etYNV7qFs0jFHUu1IRmczJtGAQLZlu8xIhBCiPwXcfp+s9x kWjqizLbm8TkeQGU95RmBFcszNFbXMQ03Aqzy0m7Pa/vsCNpwd2BiNFxYj3tNgNWLCR8EQzVKIz xo+UWSzQeO5knJEmytp7N48ltDwMT3ewPp1P8aLwpKNxgdq1ig0UCo32QWBkxpXPHvxbUrBPa/X OPd+TOTV15/2S4qjPZk5vo+yNjKG9PJGgAjf8jxhnuiNeeoa1d9j3U1YrPiCyt9Egie2apGP5T4 ZR0ZKnTaXNcIU+wbGkw57+fIttHC+r5ZT/BbfHBVpA1kmNuwCuEM2Wv40slaa3oxFLQfuWB+AWt kivBJU07YLBg9zKr/GQv5BmGb9aZxOYjrpAeWOa7gNKTtq4SlS/JTe1uUyQ8TI6fX+i3b8dUwGs d/Ks42ZqbZDspiXrW28NNl68goVyY81N2J/OWaM17eVMqCi+exqZZhtVhJTXVqB53/uCH4csPjU eRvOFdqPqoDG3eCc0YyPMeMXyiIzB+p8g== X-Received: by 2002:a05:620a:3901:b0:936:883f:e994 with SMTP id af79cd13be357-936bf9fe198mr93596185a.20.1786567615310; Wed, 12 Aug 2026 13:46:55 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id af79cd13be357-936b5dd3f5fsm213705785a.8.2026.08.12.13.46.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 13:46:54 -0700 (PDT) Date: Wed, 12 Aug 2026 16:46:53 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260812_1638/pstg-lib:20260812_1616/pstg-pwork:20260812_1638 From: Paul Moore To: =?UTF-8?q?J=C3=A9r=C3=A9my=20Jean?= , audit@vger.kernel.org Cc: Eric Paris , linux-kernel@vger.kernel.org, =?UTF-8?q?J=C3=A9r=C3=A9my=20Jean?= Subject: Re: [PATCH] audit: avoid dropping live tree ref on fsnotify rule autoremove References: <20260811220128.275783-1-Jeremy.Jean@oss.cyber.gouv.fr> In-Reply-To: <20260811220128.275783-1-Jeremy.Jean@oss.cyber.gouv.fr> On Aug 11, 2026 =?UTF-8?q?J=C3=A9r=C3=A9my=20Jean?= wrote: > > audit_del_rule() is used for both netlink deletion templates and internal > fsnotify autoremove. The former passes a parsed template which owns a > temporary tree reference; the latter passes the installed entry itself. > > The unconditional audit_put_tree() at the end of audit_del_rule() assumes > the template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify > autoremove event therefore drops the installed rule's live tree reference. > Repeating this across rules sharing the same tree can free the tree while > another rule still references it, and a later autoremove dereferences the > freed pathname while comparing rules. > > Move the temporary-tree put to audit_rule_change(), the caller that owns > deletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both > successful deletion and -ENOENT still release the parser-owned tree. > > Fixes: 34d99af52ad4 ("audit: implement audit by executable") > Assisted-by: Codex:gpt-5 > Signed-off-by: Jérémy Jean > Reviewed-by: Ricardo Robaina > Tested-by: Ricardo Robaina > --- > kernel/auditfilter.c | 6 ++---- > 1 file changed, 2 insertions(+), 4 deletions(-) Thanks for finding this and submitting a fix! This looks good to me too, so I'm going to merge this, but instead of the normal audit/stable-7.2 branch, I'm going to merge this into the audit/dev branch since we are likely only a few days away from a v7.2 release and I think it would be good to get some additional testing. I am going to tag this commit with a stable tag so it will/should get backported once it lands in Linus' tree. -- paul-moore.com