[PATCH 0/3] audit: Measure and reduce syscall filtering overhead

Stanislav Kinsburskii posted 3 patches 1 month, 3 weeks ago
MAINTAINERS                                 |   1 +
kernel/audit.h                              |   7 +
kernel/audit_tree.c                         |   1 +
kernel/audit_watch.c                        |   2 +
kernel/auditfilter.c                        | 140 +++++++++++------
kernel/auditsc.c                            |  13 ++
tools/testing/selftests/Makefile            |   1 +
tools/testing/selftests/audit/.gitignore    |   2 +
tools/testing/selftests/audit/Makefile      |   9 ++
tools/testing/selftests/audit/README        |  30 ++++
tools/testing/selftests/audit/audit_bench.c | 227 ++++++++++++++++++++++++++++
11 files changed, 389 insertions(+), 44 deletions(-)
[PATCH 0/3] audit: Measure and reduce syscall filtering overhead
Posted by Stanislav Kinsburskii 1 month, 3 weeks ago
This series adds a repeatable microbenchmark for audit's fixed syscall
overhead and uses it to address two cases where audit continues doing work
which cannot produce a record.

Patch 1 adds audit_bench, a manually run getpid(2) microbenchmark under
tools/testing/selftests/audit.  It leaves policy management to the caller
so the same workload can measure different rule configurations without
silently changing the system policy.

Patch 2 fixes audit_n_rules and audit_signals accounting when rules are
removed automatically with a watch or tree, or after an LSM rule update
fails.  These paths could leave the counters nonzero after the last
applicable rule had disappeared, causing every subsequent syscall to
allocate a non-dummy audit context.  It also centralizes rule accounting
so all rule removal paths share the same bookkeeping.

The median getpid latency in the same unpinned VM was:

                                  no rules   stale state   fixed
  automatically removed watch       38 ns       55 ns      38 ns
  automatically removed tree        38 ns       59 ns      38 ns

Patch 3 builds on those lifecycle helpers.  It maintains an aggregate mask
of the syscall numbers present in exit rules and checks that mask before
walking the exit filter list.  The mask is architecture-independent and
therefore conservative: overlapping syscall numbers may cause an
unnecessary scan, but cannot suppress a match.

For an unrelated getpid workload, the median latency scaled as follows:

  exit rules                         1       32      128      256
  before                            55 ns    71 ns   428 ns   791 ns
  after                             55 ns    55 ns    55 ns    55 ns

The aggregate mask is updated through the centralized accounting helpers.
Insertion sets the relevant bits before publishing the rule with
list_add_rcu(); removal unlinks the rule before clearing them.  This keeps
the lockless rejection test conservative during concurrent rule changes.

The series does not change the audit userspace ABI or rule matching
semantics.  The benchmark and complete reproduction procedures are
documented in the individual patches.

---
Stanislav Kinsburskii (3):
      selftests/audit: Add syscall overhead benchmark
      audit: Fix filter rule accounting after automatic removal
      audit: Skip exit filtering for syscalls without rules

 MAINTAINERS                                 |   1 +
 kernel/audit.h                              |   7 +
 kernel/audit_tree.c                         |   1 +
 kernel/audit_watch.c                        |   2 +
 kernel/auditfilter.c                        | 140 +++++++++++------
 kernel/auditsc.c                            |  13 ++
 tools/testing/selftests/Makefile            |   1 +
 tools/testing/selftests/audit/.gitignore    |   2 +
 tools/testing/selftests/audit/Makefile      |   9 ++
 tools/testing/selftests/audit/README        |  30 ++++
 tools/testing/selftests/audit/audit_bench.c | 227 ++++++++++++++++++++++++++++
 11 files changed, 389 insertions(+), 44 deletions(-)
---
base-commit: ea2bff00da89d7767d677bb68470130ba96f4928
change-id: 20260806-audit-96a1e71d38b1

Best regards,
-- 
Stanislav Kinsburskii <skinsburskii@gmail.com>
Re: [PATCH 0/3] audit: Measure and reduce syscall filtering overhead
Posted by Stanislav Kinsburskii 1 month ago
On Thu, Aug 06, 2026 at 06:01:18PM -0700, Stanislav Kinsburskii wrote:
> This series adds a repeatable microbenchmark for audit's fixed syscall
> overhead and uses it to address two cases where audit continues doing work
> which cannot produce a record.
> 

A gentle ping on this series.

Thanks,
Stanislav

> Patch 1 adds audit_bench, a manually run getpid(2) microbenchmark under
> tools/testing/selftests/audit.  It leaves policy management to the caller
> so the same workload can measure different rule configurations without
> silently changing the system policy.
> 
> Patch 2 fixes audit_n_rules and audit_signals accounting when rules are
> removed automatically with a watch or tree, or after an LSM rule update
> fails.  These paths could leave the counters nonzero after the last
> applicable rule had disappeared, causing every subsequent syscall to
> allocate a non-dummy audit context.  It also centralizes rule accounting
> so all rule removal paths share the same bookkeeping.
> 
> The median getpid latency in the same unpinned VM was:
> 
>                                   no rules   stale state   fixed
>   automatically removed watch       38 ns       55 ns      38 ns
>   automatically removed tree        38 ns       59 ns      38 ns
> 
> Patch 3 builds on those lifecycle helpers.  It maintains an aggregate mask
> of the syscall numbers present in exit rules and checks that mask before
> walking the exit filter list.  The mask is architecture-independent and
> therefore conservative: overlapping syscall numbers may cause an
> unnecessary scan, but cannot suppress a match.
> 
> For an unrelated getpid workload, the median latency scaled as follows:
> 
>   exit rules                         1       32      128      256
>   before                            55 ns    71 ns   428 ns   791 ns
>   after                             55 ns    55 ns    55 ns    55 ns
> 
> The aggregate mask is updated through the centralized accounting helpers.
> Insertion sets the relevant bits before publishing the rule with
> list_add_rcu(); removal unlinks the rule before clearing them.  This keeps
> the lockless rejection test conservative during concurrent rule changes.
> 
> The series does not change the audit userspace ABI or rule matching
> semantics.  The benchmark and complete reproduction procedures are
> documented in the individual patches.
> 
> ---
> Stanislav Kinsburskii (3):
>       selftests/audit: Add syscall overhead benchmark
>       audit: Fix filter rule accounting after automatic removal
>       audit: Skip exit filtering for syscalls without rules
> 
>  MAINTAINERS                                 |   1 +
>  kernel/audit.h                              |   7 +
>  kernel/audit_tree.c                         |   1 +
>  kernel/audit_watch.c                        |   2 +
>  kernel/auditfilter.c                        | 140 +++++++++++------
>  kernel/auditsc.c                            |  13 ++
>  tools/testing/selftests/Makefile            |   1 +
>  tools/testing/selftests/audit/.gitignore    |   2 +
>  tools/testing/selftests/audit/Makefile      |   9 ++
>  tools/testing/selftests/audit/README        |  30 ++++
>  tools/testing/selftests/audit/audit_bench.c | 227 ++++++++++++++++++++++++++++
>  11 files changed, 389 insertions(+), 44 deletions(-)
> ---
> base-commit: ea2bff00da89d7767d677bb68470130ba96f4928
> change-id: 20260806-audit-96a1e71d38b1
> 
> Best regards,
> -- 
> Stanislav Kinsburskii <skinsburskii@gmail.com>
>
Re: [PATCH 0/3] audit: Measure and reduce syscall filtering overhead
Posted by Paul Moore 1 month ago
On Sun, Aug 23, 2026 at 2:10 PM Stanislav Kinsburskii
<skinsburskii@gmail.com> wrote:
> On Thu, Aug 06, 2026 at 06:01:18PM -0700, Stanislav Kinsburskii wrote:
> > This series adds a repeatable microbenchmark for audit's fixed syscall
> > overhead and uses it to address two cases where audit continues doing work
> > which cannot produce a record.
>
> A gentle ping on this series.

As I just mentioned to another submitter, your patch hit the mailing
list at a time when the audit/dev branch was closed to everything
except for critical fixes.  We have a doc, listed in the audit
MAINTAINERS entry, which describes the management of the audit tree
and our processes:

https://github.com/linux-audit/audit-kernel/blob/main/README.md

Beyond that, while I have briefly looked at your patchset, I haven't
had a chance yet to properly review it.  Given a quick glance, patch
2/3 seems good and reasonable; it even cleans up some macro ugliness,
which is very nice.  I'm not sure about enshrining an audit benchmark
in the kernel selftests, as you do in patch 1/3, although it might be
worthwhile as part of the audit-testsuite; I want to think on that a
bit more.  In the past others have proposed similar things as you've
done in patch 3/3, but I really dislike the idea of adding more
filtering to the audit filter; I'd much rather see what we can do to
fix/improve the existing filtering.

Anyway, that's where things are at, but it basically boils down to
"yes, I've seen your patches, and no I haven't finished reviewing them
yet; your patience is appreciated.".

--
paul-moore.com