[PATCH] apparmor: resolve pivotroot paths before the failure audit
From: Adriano Cordova
Date: Mon Sep 28 2026 - 15:09:31 EST
build_pivotroot() stores the new and old path names in the audit data
while it mediates a transition, but it returns early for unconfined
profiles and profiles that do not mediate mounts. Resolve the names in
the failure path in that case before the audit record is emitted.
Signed-off-by: Adriano Cordova <adrianox@xxxxxxxxx>
---
security/apparmor/mount.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/security/apparmor/mount.c b/security/apparmor/mount.c
index 4ed7b9136beb..cd869a07335b 100644
--- a/security/apparmor/mount.c
+++ b/security/apparmor/mount.c
@@ -698,9 +698,18 @@ int aa_pivotroot(const struct cred *subj_cred, struct aa_label *label,
return error;
fail:
- /* TODO: add back in auditing of new_name and old_name,
- * needs lifting of name lookup out of profile cb
- */
+ if (!ad.name) {
+ struct aa_profile *p = labels_profile(label);
+
+ aa_path_name(new_path, path_flags(p, new_path), new_buffer,
+ &ad.name, &ad.info, p->disconnected);
+ }
+ if (!ad.mnt.src_name) {
+ struct aa_profile *p = labels_profile(label);
+
+ aa_path_name(old_path, path_flags(p, old_path), old_buffer,
+ &ad.mnt.src_name, &ad.info, p->disconnected);
+ }
ad.mnt.trans = target->hname;
error = aa_audit_perm_error(label, AA_MAY_PIVOTROOT, error, &ad,
audit_cb);
--
2.51.0