On Thu, Aug 6, 2026 at 6:17 PM Richard Guy Briggs <[email protected]> wrote: > > Between the actual process startup (fork systemd) and the executable file > replacement (exec), systemd sets a temporary file name (executable file > name in parentheses). If an auditable system call occurs at this point, > the audit context will latch the temporary process name into the cache. > This name will not change again. The patch clears proctitle into the > audit cache when the exec call is made, allowing the new process name to > be latched. > > Suggested-by: Roman Dolgikh <[email protected]> > Link: > https://github.com/user-attachments/files/20751461/fix_audit_proctitle.txt > Link: https://github.com/linux-audit/audit-kernel/issues/170 > Signed-off-by: Richard Guy Briggs <[email protected]> > --- > Changelog: > v2: simplified to call single use directly before need in audit_bimprm > --- > kernel/auditsc.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/kernel/auditsc.c b/kernel/auditsc.c > index 6610e667c728..c12b5dfcb279 100644 > --- a/kernel/auditsc.c > +++ b/kernel/auditsc.c > @@ -2601,6 +2601,8 @@ void __audit_bprm(struct linux_binprm *bprm) > { > struct audit_context *context = audit_context(); > > + /* clear proctitle in audit context to allow replacement */ > + audit_proctitle_free(audit_context());
Since we already got the context right above, it would probably be better to use the context var instead to avoid calling audit_context() again. Otherwise looks good to me. Reviewed-by: Ricardo Robaina <[email protected]> > context->type = AUDIT_EXECVE; > context->execve.argc = bprm->argc; > } > -- > 2.43.5 > > -Ricardo

