On Tue, Jul 14, 2026 at 3:33 PM Richard Guy Briggs <[email protected]> wrote:
> On 2026-07-03 09:25, Ricardo Robaina wrote:
> > Modern mount tools (util-linux >= 2.39.1) use the new mount API
> > (fsopen, fsconfig, fsmount, move_mount) instead of the legacy mount(2)
> > syscall. The generic SYSCALL audit record logs the fsopen syscall but
> > does not capture the filesystem name string, creating an audit gap for
> > filesystem mount operations.
> >
> > Add an FSOPEN auxiliary record that logs the dereferenced filesystem
> > name string passed to fsopen(2).
> >
> >   type=SYSCALL ... : arch=x86_64 syscall=fsopen ... a1=FSOPEN_CLOEXEC
> >   type=FSOPEN  ... : fs_name="tmpfs"
> >
> > Link: https://github.com/linux-audit/audit-kernel/issues/152
> > Signed-off-by: Ricardo Robaina <[email protected]>
>
> Reviewed-by: Richard Guy Briggs <[email protected]>
>
> > ---
> > Changes in v2:
> > - Better placement of audit_log_fsopen() call to avoid UAF.
> >
> >  fs/fsopen.c                |  3 +++
> >  include/linux/audit.h      | 10 ++++++++++
> >  include/uapi/linux/audit.h |  1 +
> >  kernel/auditsc.c           | 13 +++++++++++++
> >  4 files changed, 27 insertions(+)

My apologies, this patch fell between the cracks, but it looks good to me.

As this patch touches both the audit and VFS code, I've merged this
via a topic branch in the audit tree, topic-7.3-audit_fsopen.  The
branch will remain static and it will be included in the audit/next
branch as well as the audit PR for the upcoming merge window.

-- 
paul-moore.com

Reply via email to