On Tue, Jul 14, 2026 at 3:33 PM Richard Guy Briggs <[email protected]> wrote: > On 2026-07-03 09:25, Ricardo Robaina wrote: > > Modern mount tools (util-linux >= 2.39.1) use the new mount API > > (fsopen, fsconfig, fsmount, move_mount) instead of the legacy mount(2) > > syscall. The generic SYSCALL audit record logs the fsopen syscall but > > does not capture the filesystem name string, creating an audit gap for > > filesystem mount operations. > > > > Add an FSOPEN auxiliary record that logs the dereferenced filesystem > > name string passed to fsopen(2). > > > > type=SYSCALL ... : arch=x86_64 syscall=fsopen ... a1=FSOPEN_CLOEXEC > > type=FSOPEN ... : fs_name="tmpfs" > > > > Link: https://github.com/linux-audit/audit-kernel/issues/152 > > Signed-off-by: Ricardo Robaina <[email protected]> > > Reviewed-by: Richard Guy Briggs <[email protected]> > > > --- > > Changes in v2: > > - Better placement of audit_log_fsopen() call to avoid UAF. > > > > fs/fsopen.c | 3 +++ > > include/linux/audit.h | 10 ++++++++++ > > include/uapi/linux/audit.h | 1 + > > kernel/auditsc.c | 13 +++++++++++++ > > 4 files changed, 27 insertions(+)
My apologies, this patch fell between the cracks, but it looks good to me. As this patch touches both the audit and VFS code, I've merged this via a topic branch in the audit tree, topic-7.3-audit_fsopen. The branch will remain static and it will be included in the audit/next branch as well as the audit PR for the upcoming merge window. -- paul-moore.com

