From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f175.google.com (mail-qk1-f175.google.com [209.85.222.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 15DEA3AD537 for ; Mon, 17 Aug 2026 23:16:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.175 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787008594; cv=none; b=jwOojVPA/WxcunPlLc/xnDFl2Tgi5mVKeYgI7yaBEQQYItC9PGQlofFlSYR2wnXDkf2WYY8g+9ejcur8QOLrj3gIq9UdzCKw1hOvOAefYUJdfhoNlBK9/ff98Q/FE3kg3KEvkBEMD5HGxbiHbae73PH7ce2BXPfn8ng7JjqKME0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787008594; c=relaxed/simple; bh=zous+kJOvu0pQ5vWoBLAWvfbF20qVCi9FazL4EQa4IE=; h=Date:Message-ID:From:To:Cc:Subject; b=D7HmbXZQ+YCvceoWMz8lTu7kovVcTQlwVlyStCA/FlZkGV+kKr8cvdj6kEldqlZmwyaD+VWzy3DkwXJDLLyTfOC0foQ8O4tP0pFfpXBVRhI0A4EBB7sQ4uH9ttuvAKFwf7JHt8tSnQuzHAMdEm/+8kJCzEWdJ6/kOBUxoUz8tkI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=He1Y+WFM; arc=none smtp.client-ip=209.85.222.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="He1Y+WFM" Received: by mail-qk1-f175.google.com with SMTP id af79cd13be357-92e57a753f9so330089585a.2 for ; Mon, 17 Aug 2026 16:16:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1787008592; x=1787613392; darn=vger.kernel.org; h=subject:cc:to:from:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rHAbNp5NOybfUHThKAx6tAvckbqh/5pUlxMdpjuHZS4=; b=He1Y+WFMrVhAwbwz6VktgNN/f/5QyikFj3rA7tcpKHUVt9L7T60vuaaxYwhDqQW2z0 t6m7rYykL25brPHF0vElLB1NyKEcFJIepEyExKfjp28dRA/FDDl3g3SUa9u7Dzfi1MLl M5oEBKqoCnsK9bfwC1rxKn/LDFe5k/k4bqyis4UiRNPawuD6jkgIGKhzcoYofqQMu1p/ u4VIVA/KAG0S6/jtCvBONc6/SNBIpYqW/mgeLy0i0aP9nv/UyD5KJmL9Sq3UX//epr4x VzGbLK1euQ+7LXsMHS8MqDPv5GE9wtpDJTcS/Is+gBIaJz53o7wQomt/44Mhcp2q13iJ pAIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787008592; x=1787613392; h=subject:cc:to:from:message-id:date:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rHAbNp5NOybfUHThKAx6tAvckbqh/5pUlxMdpjuHZS4=; b=XCzVU5IRnNmCw4paYzsWHkWsrZ/1GvQJAy5vyzCzhyjyw+n9Hd9CzCfKcG19Th1oMU 0E/pfJFWVIx7oQgDsrWMfxQ8SDtX4IqDfVGzUIbCl8p6OLXxwRjIWXoCGeTfDRw3XpRl bgGmUSFZM64zmYLRkOoMPICVCMo2ypn1EhUQUhTtmT1kCzymQ9dA7gDTCSCZdNbgFDpI KRyCEFG03dvz1l2mXIc1Q5VHK+NkVi7GoYBIdYCiaDSS9F8cUm7phH40B/h5a4j6eYrB tvvsncKGZb65XeWCafkQ7C+oikkbtqYlBNAFGZ7vrAt19F2mnJuFAYK0kEKMLzV6aAyz 0qsg== X-Forwarded-Encrypted: i=1; AHgh+RoWqfExM/yGN0EtQ5LrVIEOHMWK8ifnZg6TchP5gdK3KpU7ftSanaG/G7CEoEVdY5ZjYl71LOckaIV0OU4=@vger.kernel.org X-Gm-Message-State: AOJu0Yy96KHpuGZR+T9r/dcNDtLx0yVs2O4zG1zRuQgmdKi5fLToObtj onGTIWY4W/dV6zQVnM3Nhclk1SwFVPDfT+ymQUtwx7PW9mQyCRgPF+DTSpBIk6CPQQ== X-Gm-Gg: AR+sD12AaIh3qlG2Nz86pRLjSTON2nyJkVQhpoci8ASam0dgutNP9VABM1nC1s4ni7r WGF5sfIH3r3Ge5NUEtHicUSZmwCXawVGgAojapcZtPqdslgXf8lGGUwCb1sh5V6alEONVU9nBW9 cgB2MwvDOleV+Oh0WLXPg4w8IySfWrJCc6kjhxmdDDfAwDPveU0SpSUO7QgPsbu9SP7k7ZrWNoZ KQmQ91ulZoB6Bh8tnYc6UZS/DdEuTjFxh+qOQ0GS/q1OcWny4/Imkhy9/WpPQkwFw6OJiJ/X+AM PD8YiCi+uF4qGffgevm5AFSkPaFufNLGt/PZ/HWh98ZF25Cf2D39spiZA579pEUms/BpxkSwy5y NraT8t1zsuP0lm662oKYcnpe49pygENBRdQ5TWJROrlkgRrJ5E+qZqeo7b47yzKAnNWy8K+r3CI FxMGHDhJyBnMK69rh1Yfzume3qK9g1WZa4ofOPrxbs1zkZLMiru8R2tc7xrnzxbUWhBVxF/hcWk ftHzbaBAaKkj44kbvxFugMurli4UPXHvFs2Kg9yhVuq X-Received: by 2002:a05:620a:45a0:b0:92e:6b16:6a0a with SMTP id af79cd13be357-936d231102dmr2889889985a.40.1787008591961; Mon, 17 Aug 2026 16:16:31 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id af79cd13be357-937010d62casm197479485a.12.2026.08.17.16.16.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 16:16:31 -0700 (PDT) Date: Mon, 17 Aug 2026 19:16:30 -0400 Message-ID: From: Paul Moore To: Linus Torvalds Cc: audit@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [GIT PULL] audit/audit-pr-20260814 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Linus, Four audit patches for the Linux v7.3 merge window, the highlights are below: - Drop BUG_ON() assertions from two functions While I don't recall any bug reports from either of these assertions in recent memory, neither of these checks warrant the kernel panic that could result from BUG_ON(). One of the BUG_ON() calls is converted to a WARN_ON_ONCE() and the other to a lockdep assertion. - Fix an audit tree reference counting problem Fix a corner case where audit could end up unintentionally dropping the last reference to an audit tree while the tree was still in use. We should probably revisit the audit tree handling code in full, but this patch works, and should be easy to backport to stable trees and downstream kernels. - Update the audit syscall classification tables Add some missing syscalls to the PERM class. Paul -- The following changes since commit dc59e4fea9d83f03bad6bddf3fa2e52491777482: Linux 7.2-rc1 (2026-06-28 12:01:31 -0700) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit.git tags/audit-pr-20260814 for you to fetch changes up to 783f0f0974c156aca630f4ffff248671082a098d: audit: avoid dropping live tree ref on fsnotify rule autoremove (2026-08-12 16:46:55 -0400) ---------------------------------------------------------------- audit/stable-7.3 PR 20260814 ---------------------------------------------------------------- Jérémy Jean (1): audit: avoid dropping live tree ref on fsnotify rule autoremove Ricardo Robaina (3): audit: add missing syscalls to PERM class tables audit: drop BUG_ON() from audit_add_to_parent() audit: drop BUG_ON() from audit_signal_info_syscall() include/asm-generic/audit_change_attr.h | 3 ++ include/asm-generic/audit_read.h | 31 ++++++++++++++++++++++++ include/asm-generic/audit_write.h | 3 ++ kernel/audit_watch.c | 2 - kernel/auditfilter.c | 6 +--- kernel/auditsc.c | 3 +- 6 files changed, 42 insertions(+), 6 deletions(-) -- paul-moore.com