[PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record

Ricardo Robaina posted 13 patches 1 month, 2 weeks ago
There is a newer version of this series
arch/alpha/kernel/ptrace.c      |  3 ++-
arch/arm/kernel/ptrace.c        |  2 +-
arch/arm64/kernel/ptrace.c      |  3 ++-
arch/csky/kernel/ptrace.c       |  3 ++-
arch/microblaze/kernel/ptrace.c |  3 ++-
arch/mips/kernel/ptrace.c       | 11 ++++++++---
arch/openrisc/kernel/ptrace.c   |  3 ++-
arch/parisc/kernel/ptrace.c     |  7 +++++--
arch/sh/kernel/ptrace_32.c      |  3 ++-
arch/sparc/kernel/ptrace_64.c   |  3 ++-
arch/um/kernel/ptrace.c         |  4 +++-
arch/xtensa/kernel/ptrace.c     |  3 ++-
include/linux/audit.h           | 11 +++++++----
include/linux/entry-common.h    |  3 ++-
include/uapi/linux/audit.h      |  2 ++
kernel/audit.h                  |  2 +-
kernel/auditfilter.c            |  2 ++
kernel/auditsc.c                | 31 ++++++++++++++++++++-----------
18 files changed, 67 insertions(+), 32 deletions(-)
[PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record
Posted by Ricardo Robaina 1 month, 2 weeks ago
The SYSCALL record currently logs only four of the six syscall
arguments (a0-a3), silently discarding the remaining two. This
leads to the need for auxiliary records when audit-relevant
data lands in the 5th or 6th argument of a syscall.

This series extends the SYSCALL record to log all six arguments,
by adding arguments a4 and a5 inline within the existing record.

The audit testsuite runs successfully:

 # make test
 make -C tests test
 chmod +x */test
 Running as   user    root
        with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
        on   system  Fedora

 amcast_joinpart/test ................. ok   
 backlog_wait_time_actual_reset/test .. ok   
 bpf/test ............................. ok   
 coredump/test ........................ ok   
 exec_execve/test ..................... ok   
 exec_name/test ....................... ok     
 fanotify/test ........................ ok   
 field_compare/test ................... ok     
 file_create/test ..................... ok   
 file_delete/test ..................... ok   
 file_permission/test ................. ok   
 file_rename/test ..................... ok   
 filter_device/test ................... ok     
 filter_exclude/test .................. ok     
 filter_exit/test ..................... ok   
 filter_inode/test .................... ok   
 filter_saddr_fam/test ................ ok   
 filter_sessionid/test ................ ok   
 io_uring/test ........................ ok   
 login_tty/test ....................... ok   
 lost_reset/test ...................... ok   
 netfilter_pkt/test ................... ok     
 signal/test .......................... ok   
 syscalls_file/test ................... ok   
 syscall_module/test .................. ok   
 syscall_socketcall/test .............. ok   
 time_change/test ..................... ok     
 user_msg/test ........................ ok   
 All tests successful.
 Result: PASS

Ricardo Robaina (13):
  audit: log all six syscall arguments in the SYSCALL record
  alpha: pass all six syscall args to audit_syscall_entry()
  arm: pass all six syscall args to audit_syscall_entry()
  arm64: pass all six syscall args to audit_syscall_entry()
  csky: pass all six syscall args to audit_syscall_entry()
  microblaze: pass all six syscall args to audit_syscall_entry()
  mips: pass all six syscall args to audit_syscall_entry()
  openrisc: pass all six syscall args to audit_syscall_entry()
  parisc: pass all six syscall args to audit_syscall_entry()
  sh: pass all six syscall args to audit_syscall_entry()
  sparc64: pass all six syscall args to audit_syscall_entry()
  um: pass all six syscall args to audit_syscall_entry()
  xtensa: pass all six syscall args to audit_syscall_entry()

 arch/alpha/kernel/ptrace.c      |  3 ++-
 arch/arm/kernel/ptrace.c        |  2 +-
 arch/arm64/kernel/ptrace.c      |  3 ++-
 arch/csky/kernel/ptrace.c       |  3 ++-
 arch/microblaze/kernel/ptrace.c |  3 ++-
 arch/mips/kernel/ptrace.c       | 11 ++++++++---
 arch/openrisc/kernel/ptrace.c   |  3 ++-
 arch/parisc/kernel/ptrace.c     |  7 +++++--
 arch/sh/kernel/ptrace_32.c      |  3 ++-
 arch/sparc/kernel/ptrace_64.c   |  3 ++-
 arch/um/kernel/ptrace.c         |  4 +++-
 arch/xtensa/kernel/ptrace.c     |  3 ++-
 include/linux/audit.h           | 11 +++++++----
 include/linux/entry-common.h    |  3 ++-
 include/uapi/linux/audit.h      |  2 ++
 kernel/audit.h                  |  2 +-
 kernel/auditfilter.c            |  2 ++
 kernel/auditsc.c                | 31 ++++++++++++++++++++-----------
 18 files changed, 67 insertions(+), 32 deletions(-)

-- 
2.55.0
Re: [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record
Posted by Will Deacon 1 month, 2 weeks ago
On Thu, Aug 13, 2026 at 02:02:50PM -0300, Ricardo Robaina wrote:
> The SYSCALL record currently logs only four of the six syscall
> arguments (a0-a3), silently discarding the remaining two. This
> leads to the need for auxiliary records when audit-relevant
> data lands in the 5th or 6th argument of a syscall.
> 
> This series extends the SYSCALL record to log all six arguments,
> by adding arguments a4 and a5 inline within the existing record.
> 
> The audit testsuite runs successfully:
> 
>  # make test
>  make -C tests test
>  chmod +x */test
>  Running as   user    root
>         with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
>         on   system  Fedora
> 
>  amcast_joinpart/test ................. ok   
>  backlog_wait_time_actual_reset/test .. ok   
>  bpf/test ............................. ok   
>  coredump/test ........................ ok   
>  exec_execve/test ..................... ok   
>  exec_name/test ....................... ok     
>  fanotify/test ........................ ok   
>  field_compare/test ................... ok     
>  file_create/test ..................... ok   
>  file_delete/test ..................... ok   
>  file_permission/test ................. ok   
>  file_rename/test ..................... ok   
>  filter_device/test ................... ok     
>  filter_exclude/test .................. ok     
>  filter_exit/test ..................... ok   
>  filter_inode/test .................... ok   
>  filter_saddr_fam/test ................ ok   
>  filter_sessionid/test ................ ok   
>  io_uring/test ........................ ok   
>  login_tty/test ....................... ok   
>  lost_reset/test ...................... ok   
>  netfilter_pkt/test ................... ok     
>  signal/test .......................... ok   
>  syscalls_file/test ................... ok   
>  syscall_module/test .................. ok   
>  syscall_socketcall/test .............. ok   
>  time_change/test ..................... ok     
>  user_msg/test ........................ ok   
>  All tests successful.
>  Result: PASS
> 
> Ricardo Robaina (13):
>   audit: log all six syscall arguments in the SYSCALL record
>   alpha: pass all six syscall args to audit_syscall_entry()
>   arm: pass all six syscall args to audit_syscall_entry()
>   arm64: pass all six syscall args to audit_syscall_entry()
>   csky: pass all six syscall args to audit_syscall_entry()
>   microblaze: pass all six syscall args to audit_syscall_entry()
>   mips: pass all six syscall args to audit_syscall_entry()
>   openrisc: pass all six syscall args to audit_syscall_entry()
>   parisc: pass all six syscall args to audit_syscall_entry()
>   sh: pass all six syscall args to audit_syscall_entry()
>   sparc64: pass all six syscall args to audit_syscall_entry()
>   um: pass all six syscall args to audit_syscall_entry()
>   xtensa: pass all six syscall args to audit_syscall_entry()

Could audit make use of syscall_get_arguments() instead?

Will
Re: [PATCH 00/13] audit: log all six syscall arguments in the SYSCALL record
Posted by Ricardo Robaina 1 month, 2 weeks ago
On Fri, Aug 14, 2026 at 5:40 AM Will Deacon <will@kernel.org> wrote:
>
> On Thu, Aug 13, 2026 at 02:02:50PM -0300, Ricardo Robaina wrote:
> > The SYSCALL record currently logs only four of the six syscall
> > arguments (a0-a3), silently discarding the remaining two. This
> > leads to the need for auxiliary records when audit-relevant
> > data lands in the 5th or 6th argument of a syscall.
> >
> > This series extends the SYSCALL record to log all six arguments,
> > by adding arguments a4 and a5 inline within the existing record.
> >
> > The audit testsuite runs successfully:
> >
> >  # make test
> >  make -C tests test
> >  chmod +x */test
> >  Running as   user    root
> >         with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
> >         on   system  Fedora
> >
> >  amcast_joinpart/test ................. ok
> >  backlog_wait_time_actual_reset/test .. ok
> >  bpf/test ............................. ok
> >  coredump/test ........................ ok
> >  exec_execve/test ..................... ok
> >  exec_name/test ....................... ok
> >  fanotify/test ........................ ok
> >  field_compare/test ................... ok
> >  file_create/test ..................... ok
> >  file_delete/test ..................... ok
> >  file_permission/test ................. ok
> >  file_rename/test ..................... ok
> >  filter_device/test ................... ok
> >  filter_exclude/test .................. ok
> >  filter_exit/test ..................... ok
> >  filter_inode/test .................... ok
> >  filter_saddr_fam/test ................ ok
> >  filter_sessionid/test ................ ok
> >  io_uring/test ........................ ok
> >  login_tty/test ....................... ok
> >  lost_reset/test ...................... ok
> >  netfilter_pkt/test ................... ok
> >  signal/test .......................... ok
> >  syscalls_file/test ................... ok
> >  syscall_module/test .................. ok
> >  syscall_socketcall/test .............. ok
> >  time_change/test ..................... ok
> >  user_msg/test ........................ ok
> >  All tests successful.
> >  Result: PASS
> >
> > Ricardo Robaina (13):
> >   audit: log all six syscall arguments in the SYSCALL record
> >   alpha: pass all six syscall args to audit_syscall_entry()
> >   arm: pass all six syscall args to audit_syscall_entry()
> >   arm64: pass all six syscall args to audit_syscall_entry()
> >   csky: pass all six syscall args to audit_syscall_entry()
> >   microblaze: pass all six syscall args to audit_syscall_entry()
> >   mips: pass all six syscall args to audit_syscall_entry()
> >   openrisc: pass all six syscall args to audit_syscall_entry()
> >   parisc: pass all six syscall args to audit_syscall_entry()
> >   sh: pass all six syscall args to audit_syscall_entry()
> >   sparc64: pass all six syscall args to audit_syscall_entry()
> >   um: pass all six syscall args to audit_syscall_entry()
> >   xtensa: pass all six syscall args to audit_syscall_entry()
>
> Could audit make use of syscall_get_arguments() instead?
>
> Will
>

Hi Will,

Thanks for reviewing this patch. Yes, I think so. I'll fix that in the v2.

Thanks,
-Ricardo