Re: [PATCH v2] audit: free proctitle in context so it can be re-set by fork on exec_binprm

From: Ricardo Robaina

Date: Fri Aug 07 2026 - 08:27:00 EST


On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <rgb@xxxxxxxxxx> wrote:
>
> Between the actual process startup (fork systemd) and the executable file
> replacement (exec), systemd sets a temporary file name (executable file
> name in parentheses). If an auditable system call occurs at this point,
> the audit context will latch the temporary process name into the cache.
> This name will not change again. The patch clears proctitle into the
> audit cache when the exec call is made, allowing the new process name to
> be latched.
>
> Suggested-by: Roman Dolgikh <rmd4work@xxxxxxx>
> Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
> Link: https://github.com/linux-audit/audit-kernel/issues/170
> Signed-off-by: Richard Guy Briggs <rgb@xxxxxxxxxx>
> ---
> Changelog:
> v2: simplified to call single use directly before need in audit_bimprm
> ---
> kernel/auditsc.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/kernel/auditsc.c b/kernel/auditsc.c
> index 6610e667c728..c12b5dfcb279 100644
> --- a/kernel/auditsc.c
> +++ b/kernel/auditsc.c
> @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
> {
> struct audit_context *context = audit_context();
>
> + /* clear proctitle in audit context to allow replacement */
> + audit_proctitle_free(audit_context());

Since we already got the context right above, it would probably be
better to use the context var instead to avoid calling audit_context()
again.

Otherwise looks good to me.

Reviewed-by: Ricardo Robaina <rrobaina@xxxxxxxxxx>

> context->type = AUDIT_EXECVE;
> context->execve.argc = bprm->argc;
> }
> --
> 2.43.5
>
>

-Ricardo