Between the actual process startup (fork systemd) and the executable file replacement (exec), systemd sets a temporary file name (executable file name in parentheses). If an auditable system call occurs at this point, the audit context will latch the temporary process name into the cache. This name will not change again. The patch clears proctitle into the audit cache when the exec call is made, allowing the new process name to be latched.
Suggested-by: Roman Dolgikh <[email protected]> Link: https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt Link: https://github.com/linux-audit/audit-kernel/issues/170 Signed-off-by: Richard Guy Briggs <[email protected]> --- Changelog: v2: simplified to call single use directly before need in audit_bimprm --- kernel/auditsc.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/kernel/auditsc.c b/kernel/auditsc.c index 6610e667c728..c12b5dfcb279 100644 --- a/kernel/auditsc.c +++ b/kernel/auditsc.c @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm) { struct audit_context *context = audit_context(); + /* clear proctitle in audit context to allow replacement */ + audit_proctitle_free(audit_context()); context->type = AUDIT_EXECVE; context->execve.argc = bprm->argc; } -- 2.43.5

