Re: [PATCH v3] audit: free proctitle in context so it can be re-set by fork on exec_binprm
From: Bradley Morgan
Date: Thu Aug 20 2026 - 16:52:29 EST
On 18 August 2026 19:28:53 BST, Richard Guy Briggs <rgb@xxxxxxxxxx> wrote:
>Between the actual process startup (fork systemd) and the executable file
>replacement (exec), systemd sets a temporary file name (executable file
>name in parentheses). If an auditable system call occurs at this point,
>the audit context will latch the temporary process name into the cache.
>This name will not change again. The patch clears proctitle into the
>audit cache when the exec call is made, allowing the new process name to
>be latched.
>
>Suggested-by: Roman Dolgikh <rmd4work@xxxxxxx>
>Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt
>Link: https://github.com/linux-audit/audit-kernel/issues/170
>Signed-off-by: Richard Guy Briggs <rgb@xxxxxxxxxx>
LGTM, cheers
Reviewed-by: Bradley Morgan <include@xxxxxxxxx>
>Reviewed-by: Ricardo Robaina <rrobaina@xxxxxxxxxx>
>---
> kernel/auditsc.c | 2 ++
> 1 file changed, 2 insertions(+)
>
>diff --git a/kernel/auditsc.c b/kernel/auditsc.c
>index 2b9ce0b52511..ee7e53d2cd52 100644
>--- a/kernel/auditsc.c
>+++ b/kernel/auditsc.c
>@@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm)
> {
> struct audit_context *context = audit_context();
>
>+ /* clear proctitle in audit context to allow replacement */
>+ audit_proctitle_free(context);
> context->type = AUDIT_EXECVE;
> context->execve.argc = bprm->argc;
> }
>
Thanks!