On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <[email protected]> wrote:
>
> Between the actual process startup (fork systemd) and the executable file
> replacement (exec), systemd sets a temporary file name (executable file
> name in parentheses). If an auditable system call occurs at this point,
> the audit context will latch the temporary process name into the cache.
> This name will not change again. The patch clears proctitle into the
> audit cache when the exec call is made, allowing the new process name to
> be latched.
>
> Suggested-by: Roman Dolgikh <[email protected]>
> Link: 
> https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
> Link: https://github.com/linux-audit/audit-kernel/issues/170
> Signed-off-by: Richard Guy Briggs <[email protected]>
> ---
> Changelog:
> v2: simplified to call single use directly before need in audit_bimprm
> ---
>  kernel/auditsc.c | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/kernel/auditsc.c b/kernel/auditsc.c
> index 6610e667c728..c12b5dfcb279 100644
> --- a/kernel/auditsc.c
> +++ b/kernel/auditsc.c
> @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
>  {
>         struct audit_context *context = audit_context();
>
> +       /* clear proctitle in audit context to allow replacement */
> +       audit_proctitle_free(audit_context());

Since we already got the context right above, it would probably be
better to use the context var instead to avoid calling audit_context()
again.

Otherwise looks good to me.

Reviewed-by: Ricardo Robaina <[email protected]>

>         context->type = AUDIT_EXECVE;
>         context->execve.argc = bprm->argc;
>  }
> --
> 2.43.5
>
>

-Ricardo


Reply via email to