From nobody Mon Sep 28 19:23:43 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AAEB5485CC6 for ; Tue, 18 Aug 2026 18:29:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787077767; cv=none; b=VvcOPMbIABxFTFWUYyf4yP1BgttyyYlHsVE618hfMme7/kzsNhunirTvB7rp7YVX23AAGc4cMpPNzswDqmpDvdaKyS2ko5tvnnkw8j0H5vJ7oVzN/shg+/b183YHjf5neRA1wKt9aG1NrFMwJ0bA0DXRB5+nWoCLN5+/JqGeXAg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787077767; c=relaxed/simple; bh=k/+ApJt3P3zMqFz21NN375NrfmjJgVvN8ar7Y/vPu4o=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-type; b=pvi6nyt0YpXf+VnKBWELz7VDQd+JMd1nazXIZq393c1MOYsOjMFMWV5ie6CieeJlxa6Ul0cWdPJvwdqWttHgp3VIBlelBBTedi0ngE/zLuPsI5O9s/a6znZYUiaEEMLfoi687yM4FIpXcdR2TULqrGrU2ZF9vue+JlpUXZ3x02U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=IvOQ0mIb; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="IvOQ0mIb" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787077764; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=E6WoPLdui5hJShuUBNt4cps69fDTpty5hKi5ZAV1Mr8=; b=IvOQ0mIbd0+dxf1I4hpQvjGBMHFk4WHUVJCegwYBbNMhHfN8KTkQzmwX+7Y24DdfG7Cv9I qSWpjeHPbhpWgWZMZphMxtLbBGZt+vqyaXdR+AA4oq0W3CE44GQfDzS/nf299JG7LZN7Kh Ae3vG+Xro/4wPk3PlhcL3TUNaL6UMt0= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-561-iBRWyX7LN3iXibK8SivaWA-1; Tue, 18 Aug 2026 14:29:14 -0400 X-MC-Unique: iBRWyX7LN3iXibK8SivaWA-1 X-Mimecast-MFC-AGG-ID: iBRWyX7LN3iXibK8SivaWA_1787077752 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 439E318001E6; Tue, 18 Aug 2026 18:29:12 +0000 (UTC) Received: from madcap2.tricolour.com (unknown [10.22.74.2]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 61E441800346; Tue, 18 Aug 2026 18:29:07 +0000 (UTC) From: Richard Guy Briggs To: Linux-Audit Mailing List , LKML , linux-fsdevel@vger.kernel.org, Linux Kernel Audit Mailing List Cc: Paul Moore , Eric Paris , Steve Grubb , Richard Guy Briggs , Roman Dolgikh , Ricardo Robaina Subject: [PATCH v3] audit: free proctitle in context so it can be re-set by fork on exec_binprm Date: Tue, 18 Aug 2026 14:28:53 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Content-Type: text/plain; charset="utf-8" Between the actual process startup (fork systemd) and the executable file replacement (exec), systemd sets a temporary file name (executable file name in parentheses). If an auditable system call occurs at this point, the audit context will latch the temporary process name into the cache. This name will not change again. The patch clears proctitle into the audit cache when the exec call is made, allowing the new process name to be latched. Suggested-by: Roman Dolgikh Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitl= e.txt Link: https://github.com/linux-audit/audit-kernel/issues/170 Signed-off-by: Richard Guy Briggs Reviewed-by: Ricardo Robaina Reviewed-by: Bradley Morgan --- kernel/auditsc.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/kernel/auditsc.c b/kernel/auditsc.c index 2b9ce0b52511..ee7e53d2cd52 100644 --- a/kernel/auditsc.c +++ b/kernel/auditsc.c @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm) { struct audit_context *context =3D audit_context(); =20 + /* clear proctitle in audit context to allow replacement */ + audit_proctitle_free(context); context->type =3D AUDIT_EXECVE; context->execve.argc =3D bprm->argc; } --=20 2.43.5