mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Richard Guy Briggs <rgb@redhat.com>
To: Linux-Audit Mailing List <linux-audit@lists.linux-audit.osci.io>,
	LKML <linux-kernel@vger.kernel.org>,
	linux-fsdevel@vger.kernel.org,
	Linux Kernel Audit Mailing List <audit@vger.kernel.org>
Cc: Paul Moore <paul@paul-moore.com>,
	Eric Paris <eparis@parisplace.org>,
	Steve Grubb <sgrubb@redhat.com>,
	Richard Guy Briggs <rgb@redhat.com>
Subject: [PATCH v1] audit: free proctitle in context so it can be set by fork
Date: Sun, 26 Jul 2026 17:37:14 -0400	[thread overview]
Message-ID: <d67349e701acb3125d733f833e6ef2e47c91daae.1785101356.git.rgb@redhat.com> (raw)

Original title: fixes clean proctitle in audit context on exec call

Between the actual process startup (fork systemd) and the executable file
replacement (exec), systemd sets a temporary file name (executable file
name in parentheses). If an auditable system call occurs at this point,
the audit context will latch the temporary process name into the cache.
This name will not change again. The patch clears proctitle into the
audit cache when the exec call is made, allowing the new process name to
be latched.

Suggested by Roman Dolgikh https://github.com/rmd4ctf 2025-06-11
Link: https://github.com/linux-audit/audit-kernel/issues/170.
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
---
 fs/exec.c             | 2 ++
 include/linux/audit.h | 9 +++++++++
 kernel/auditsc.c      | 4 ++--
 3 files changed, 13 insertions(+), 2 deletions(-)

diff --git a/fs/exec.c b/fs/exec.c
index b92fe7db176c..bd51489dec23 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1744,6 +1744,8 @@ static int exec_binprm(struct linux_binprm *bprm)
 			fput(exec);
 	}
 
+	/* clear proctitle in audit context to allow replacement */
+	audit_proctitle_free(audit_context());
 	audit_bprm(bprm);
 	trace_sched_process_exec(current, old_pid, bprm);
 	ptrace_event(PTRACE_EVENT_EXEC, old_vpid);
diff --git a/include/linux/audit.h b/include/linux/audit.h
index 45abb3722d30..03ae563ca348 100644
--- a/include/linux/audit.h
+++ b/include/linux/audit.h
@@ -320,6 +320,7 @@ static inline void audit_cfg_lsm(const struct lsm_id *lsmid, int flags)
 /* These are defined in auditsc.c */
 				/* Public API */
 extern int  audit_alloc(struct task_struct *task);
+extern void __audit_proctitle_free(struct audit_context *context);
 extern void __audit_free(struct task_struct *task);
 extern void __audit_uring_entry(u8 op);
 extern void __audit_uring_exit(int success, long code);
@@ -353,6 +354,11 @@ static inline bool audit_dummy_context(void)
 	void *p = audit_context();
 	return !p || *(int *)p;
 }
+static inline void audit_proctitle_free(struct audit_context *context)
+{
+	if (unlikely(!audit_dummy_context()))
+		__audit_proctitle_free(context);
+}
 static inline void audit_free(struct task_struct *task)
 {
 	if (unlikely(task->audit_context))
@@ -470,6 +476,7 @@ static inline void audit_bprm(struct linux_binprm *bprm)
 	if (unlikely(!audit_dummy_context()))
 		__audit_bprm(bprm);
 }
+
 static inline int audit_socketcall(int nargs, unsigned long *args)
 {
 	if (unlikely(!audit_dummy_context()))
@@ -605,6 +612,8 @@ static inline int audit_alloc(struct task_struct *task)
 {
 	return 0;
 }
+static inline void audit_proctitle_free(struct audit_context *context)
+{ }
 static inline void audit_free(struct task_struct *task)
 { }
 static inline void audit_uring_entry(u8 op)
diff --git a/kernel/auditsc.c b/kernel/auditsc.c
index 6610e667c728..69484ab2c8bc 100644
--- a/kernel/auditsc.c
+++ b/kernel/auditsc.c
@@ -913,7 +913,7 @@ void audit_filter_inodes(struct task_struct *tsk, struct audit_context *ctx)
 	rcu_read_unlock();
 }
 
-static inline void audit_proctitle_free(struct audit_context *context)
+void __audit_proctitle_free(struct audit_context *context)
 {
 	kfree(context->proctitle.value);
 	context->proctitle.value = NULL;
@@ -1086,7 +1086,7 @@ static inline void audit_free_context(struct audit_context *context)
 {
 	/* resetting is extra work, but it is likely just noise */
 	audit_reset_context(context);
-	audit_proctitle_free(context);
+	__audit_proctitle_free(context);
 	free_tree_refs(context);
 	kfree(context->filterkey);
 	kfree(context);
-- 
2.43.5


             reply	other threads:[~2026-07-26 21:38 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26 21:37 Richard Guy Briggs [this message]
2026-07-27  9:41 ` Christian Brauner
2026-07-28 16:16 ` Paul Moore
2026-08-06 21:15   ` Richard Guy Briggs

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d67349e701acb3125d733f833e6ef2e47c91daae.1785101356.git.rgb@redhat.com \
    --to=rgb@redhat.com \
    --cc=audit@vger.kernel.org \
    --cc=eparis@parisplace.org \
    --cc=linux-audit@lists.linux-audit.osci.io \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=paul@paul-moore.com \
    --cc=sgrubb@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®