Re: [PATCH v2] audit: add FSOPEN record to log filesystem name

From: Paul Moore

Date: Sun Oct 04 2026 - 09:18:43 EST


On Tue, Jul 14, 2026 at 3:33 PM Richard Guy Briggs <rgb@xxxxxxxxxx> wrote:
> On 2026-07-03 09:25, Ricardo Robaina wrote:
> > Modern mount tools (util-linux >= 2.39.1) use the new mount API
> > (fsopen, fsconfig, fsmount, move_mount) instead of the legacy mount(2)
> > syscall. The generic SYSCALL audit record logs the fsopen syscall but
> > does not capture the filesystem name string, creating an audit gap for
> > filesystem mount operations.
> >
> > Add an FSOPEN auxiliary record that logs the dereferenced filesystem
> > name string passed to fsopen(2).
> >
> > type=SYSCALL ... : arch=x86_64 syscall=fsopen ... a1=FSOPEN_CLOEXEC
> > type=FSOPEN ... : fs_name="tmpfs"
> >
> > Link: https://github.com/linux-audit/audit-kernel/issues/152
> > Signed-off-by: Ricardo Robaina <rrobaina@xxxxxxxxxx>
>
> Reviewed-by: Richard Guy Briggs <rgb@xxxxxxxxxx>
>
> > ---
> > Changes in v2:
> > - Better placement of audit_log_fsopen() call to avoid UAF.
> >
> > fs/fsopen.c | 3 +++
> > include/linux/audit.h | 10 ++++++++++
> > include/uapi/linux/audit.h | 1 +
> > kernel/auditsc.c | 13 +++++++++++++
> > 4 files changed, 27 insertions(+)

My apologies, this patch fell between the cracks, but it looks good to me.

As this patch touches both the audit and VFS code, I've merged this
via a topic branch in the audit tree, topic-7.3-audit_fsopen. The
branch will remain static and it will be included in the audit/next
branch as well as the audit PR for the upcoming merge window.

--
paul-moore.com