From nobody Tue Sep 29 14:54:45 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CFEFB3D5226 for ; Thu, 6 Aug 2026 21:17:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786051033; cv=none; b=ZEpXWG5vog2bRTGLYLTRmnWg2fd2RiYoMBf0RArcbEJuZzpwl+lSHq+df1BVu7eucpOhqpNy0g1/Gs5N9WYKs7OGaHYxd1A+tWlySJdt1GF+hVCLeyguT/+VYZrA26xx8IoRQs0nkHNDwCgY3HKjXoEBAw2vK7uwH28DHa2bEuA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786051033; c=relaxed/simple; bh=5giSW+VuC78TRko3EcOP03tq37ilLAxMqTC7jxgfgHY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-type; b=NOktfRfSvU2UxsrRrUwYHrbc6kBd/Jgf5O++y5x0vuLMYmVdioVNklFgExv5NxRmJXymUPVTaxy3tTevho76JbeKGYG3WMa6JxAwqsM1YaxzfcuM1H0M4WzLbAcxkuqkiFNvbn2F80eFkrxIBArfb9Z8n3XXXMSjLATnBQiQEqY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=ehvjGsW4; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="ehvjGsW4" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786051030; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2/Y/fkmMMH1hnVR5XrKLq76YlQnpc28qBAYVCT6RNms=; b=ehvjGsW4aoqwYPAqYDm+XPawOL07HImm9OS09PpjrmU45lEt/Fg2Tfaf1vt/1Auq9GHTej MqpeVHCZ41vDRt/jGEZiXDMOv7ZHpB/ZP/tkcKWbcvN3/M4eigQardsbcFZGBcJFKxMUhK miM7iJOpBUbp/8HWb3+zDdhaaTp2l2Q= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-146-e-_1UQ5NOUOrs-xNCu_0Ow-1; Thu, 06 Aug 2026 17:17:09 -0400 X-MC-Unique: e-_1UQ5NOUOrs-xNCu_0Ow-1 X-Mimecast-MFC-AGG-ID: e-_1UQ5NOUOrs-xNCu_0Ow_1786051027 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C083D18002C8; Thu, 6 Aug 2026 21:17:06 +0000 (UTC) Received: from madcap2.tricolour.com (unknown [10.22.74.4]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6797D1956049; Thu, 6 Aug 2026 21:17:04 +0000 (UTC) From: Richard Guy Briggs To: Linux-Audit Mailing List , LKML , linux-fsdevel@vger.kernel.org, Linux Kernel Audit Mailing List Cc: Paul Moore , Eric Paris , Steve Grubb , Richard Guy Briggs , Roman Dolgikh Subject: [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm Date: Thu, 6 Aug 2026 17:16:59 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Content-Type: text/plain; charset="utf-8" Between the actual process startup (fork systemd) and the executable file replacement (exec), systemd sets a temporary file name (executable file name in parentheses). If an auditable system call occurs at this point, the audit context will latch the temporary process name into the cache. This name will not change again. The patch clears proctitle into the audit cache when the exec call is made, allowing the new process name to be latched. Suggested-by: Roman Dolgikh Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitl= e.txt Link: https://github.com/linux-audit/audit-kernel/issues/170 Signed-off-by: Richard Guy Briggs Reviewed-by: Ricardo Robaina --- Changelog: v2: simplified to call single use directly before need in audit_bimprm --- kernel/auditsc.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/kernel/auditsc.c b/kernel/auditsc.c index 6610e667c728..c12b5dfcb279 100644 --- a/kernel/auditsc.c +++ b/kernel/auditsc.c @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm) { struct audit_context *context =3D audit_context(); =20 + /* clear proctitle in audit context to allow replacement */ + audit_proctitle_free(audit_context()); context->type =3D AUDIT_EXECVE; context->execve.argc =3D bprm->argc; } --=20 2.43.5