Re: [PATCH] audit: add MOVE_MOUNT auxiliary record to log mount relocation

Paul Moore <[email protected]>
Newsgroups org.kernel.vger.audit,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel
Message-ID <CAHC9VhTDsVZPfu9ZNDge+fbRLr1c4EFPKi_E8R7+N9wfvL9n5g@mail.gmail.com>
On Wed, Aug 12, 2026 at 12:01 PM Steve Grubb <[email protected]> wrote:
> On Wednesday, August 12, 2026 10:39:52 AM Eastern Daylight Time Ricardo
> Robaina wrote:
> > On Tue, Jul 28, 2026 at 6:22 PM Paul Moore <[email protected]> wrote:
> > > On Mon, Jul 13, 2026 at 1:00 PM Ricardo Robaina <[email protected]>
> wrote:
> > > > Modern mount tools (util-linux >= 2.39.1) use the new mount API
> > > > (fsopen, fsconfig, fsmount, move_mount) instead of the legacy mount(2)
> > > > syscall. The generic SYSCALL audit record logs the move_mount syscall
> > > > but does not capture the flags argument, creating an audit gap for
> > > > mount relocation operations.
> > > >
> > > > Add a MOVE_MOUNT auxiliary record that logs the flags argument passed
> > > > to move_mount(2). Pathnames and file descriptors are captured through
> > > > existing PATH records and SYSCALL record arguments.
> > > >
> > > >  ----
> > > >  type=PATH : item=0 name=/mnt/test_src inode=1 dev=00:41 ...
> > > >  type=SYSCALL : arch=x86_64 syscall=move_mount ...
> > > >  type=MOVE_MOUNT : fs_flags=0x4
> > > >  ----
> > > >  type=PATH : item=0 name=/mnt/test_dst inode=27460862 dev=fc:00 ...
> > > >  type=SYSCALL : arch=x86_64 syscall=move_mount ...
> > > >  type=MOVE_MOUNT : fs_flags=0x4
> > > >
> > > > Link: https://github.com/linux-audit/audit-kernel/issues/152
> > > > Link: https://github.com/linux-audit/audit-kernel/issues/153
> > > > Signed-off-by: Ricardo Robaina <[email protected]>
> > > > ---
> > > >
> > > >  fs/namespace.c             |  3 +++
> > > >  include/linux/audit.h      | 10 ++++++++++
> > > >  include/uapi/linux/audit.h |  1 +
> > > >  kernel/auditsc.c           | 13 +++++++++++++
> > > >  4 files changed, 27 insertions(+)
> >
> > Thanks for reviewing this patch, Paul!
> >
> > > This is because we only log the first four syscall parameters,
> > > correct?  To put this another way, if we logged all six syscall
> > > parameters this wouldn't be an issue, yes?
> >
> > Yes, that's correct.
>
> I've been aiming to reply to this and lost the original...in the case of
> mmap, yes. If we had just 5 of the passed values, we would not need a
> supplemental record just to record the fd.
>
> However, in many other syscalls, we only have pointers. Sometimes syscalls
> are designed to pass a structure with config items where some are security
> relevant. In those cases having all the args doesn't help and we still need
> the supplemental record.

True, but that is independent of logging all of the syscall
parameters.  In my opinion only logging the first four was a terrible
mistake (I know you disagree Steve) and I'd just assume we correct
that before we add an auxiliary record.

-- 
paul-moore.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.