Re: [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible

Paul Moore <[email protected]> Fri, 17 Jul 2026 17:54:34 -0400
Newsgroups org.kernel.vger.linux-security-module
Message-ID <CAHC9VhRcJGj3Pnrpmpi0uRi3ndcMVGGQorsU4dJ-vA_uQmRuQA@mail.gmail.com>
On Fri, Jul 17, 2026 at 5:52 PM Paul Moore <[email protected]> wrote:
>
> Make use of the audit_log_n_untrustedstring() function to simplify the
> code in aa_label_xaudit().
>
> Signed-off-by: Paul Moore <[email protected]>
> ---
>  security/apparmor/label.c | 5 +----
>  1 file changed, 1 insertion(+), 4 deletions(-)

Untested beyond a basic compile, but I noticed this while looking at
something else (unrelated) and wanted to send it to the list before I
forgot about it ...

> diff --git a/security/apparmor/label.c b/security/apparmor/label.c
> index 3fd384d8c41a..a165cadf8249 100644
> --- a/security/apparmor/label.c
> +++ b/security/apparmor/label.c
> @@ -1743,10 +1743,7 @@ void aa_label_xaudit(struct audit_buffer *ab, struct aa_ns *ns,
>                 str = (char *) label->hname;
>                 len = strlen(str);
>         }
> -       if (audit_string_contains_control(str, len))
> -               audit_log_n_hex(ab, str, len);
> -       else
> -               audit_log_n_string(ab, str, len);
> +       audit_log_n_untrustedstring(ab, str, len);
>
>         kfree(name);
>  }
> --
> 2.55.0

-- 
paul-moore.com