Re: [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm

Richard Guy Briggs <[email protected]>
Newsgroups org.kernel.vger.audit,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 2026-08-07 09:25, Ricardo Robaina wrote:
> On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <[email protected]> wrote:
> >
> > Between the actual process startup (fork systemd) and the executable file
> > replacement (exec), systemd sets a temporary file name (executable file
> > name in parentheses). If an auditable system call occurs at this point,
> > the audit context will latch the temporary process name into the cache.
> > This name will not change again. The patch clears proctitle into the
> > audit cache when the exec call is made, allowing the new process name to
> > be latched.
> >
> > Suggested-by: Roman Dolgikh <[email protected]>
> > Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
> > Link: https://github.com/linux-audit/audit-kernel/issues/170
> > Signed-off-by: Richard Guy Briggs <[email protected]>
> > ---
> > Changelog:
> > v2: simplified to call single use directly before need in audit_bimprm
> > ---
> >  kernel/auditsc.c | 2 ++
> >  1 file changed, 2 insertions(+)
> >
> > diff --git a/kernel/auditsc.c b/kernel/auditsc.c
> > index 6610e667c728..c12b5dfcb279 100644
> > --- a/kernel/auditsc.c
> > +++ b/kernel/auditsc.c
> > @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
> >  {
> >         struct audit_context *context = audit_context();
> >
> > +       /* clear proctitle in audit context to allow replacement */
> > +       audit_proctitle_free(audit_context());
> 
> Since we already got the context right above, it would probably be
> better to use the context var instead to avoid calling audit_context()
> again.

Yup, right you are.  Silly oversight.

> Otherwise looks good to me.
> 
> Reviewed-by: Ricardo Robaina <[email protected]>
> 
> >         context->type = AUDIT_EXECVE;
> >         context->execve.argc = bprm->argc;
> >  }
> > --
> > 2.43.5
> 
> -Ricardo

- RGB

--
Richard Guy Briggs <[email protected]>
Sr. S/W Engineer, Kernel Security, Base Operating Systems
Remote, Ottawa, Red Hat Canada
Upstream IRC: SunRaycer
Voice: +1.613.860 2354 SMS: +1.613.518.6570
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.