[PATCH v3 00/14] audit: log all six syscall arguments in the SYSCALL record

Ricardo Robaina rrobaina at redhat.com
Tue Sep 22 12:19:52 PDT 2026


The SYSCALL record currently logs only four of the six syscall
arguments (a0-a3), silently discarding the remaining two. This
leads to the need for auxiliary records when audit-relevant
data lands in the 5th or 6th argument of a syscall.

This series extends the SYSCALL record to log all six arguments,
by adding arguments a4 and a5 inline within the existing record.

Rather than plumbing two more argument registers through every
architecture's syscall entry path, audit_syscall_entry() now takes a
struct pt_regs * and retrieves all six arguments itself via
syscall_get_arguments(); the per-arch patches simply pass regs. The two
new arguments are also wired into the audit filter, so rules can match
on a4 and a5.

To keep the series bisectable, the new pt_regs-based helpers are added
first (patch 1), each architecture is converted one per patch, and the
final patch removes the legacy argument-register helpers and renames the
new ones back to audit_syscall_entry(). Every commit builds on its own.

The audit testsuite runs successfully:

 # make test
 make -C tests test
 Running as   user    root
        with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
        on   system  Fedora

 amcast_joinpart/test ................. ok
 backlog_wait_time_actual_reset/test .. ok
 bpf/test ............................. ok
 coredump/test ........................ ok
 exec_execve/test ..................... ok
 exec_name/test ....................... ok
 fanotify/test ........................ ok
 field_compare/test ................... ok
 file_create/test ..................... ok
 file_delete/test ..................... ok
 file_permission/test ................. ok
 file_rename/test ..................... ok
 filter_device/test ................... ok
 filter_exclude/test .................. ok
 filter_exit/test ..................... ok
 filter_inode/test .................... ok
 filter_saddr_fam/test ................ ok
 filter_sessionid/test ................ ok
 io_uring/test ........................ ok
 login_tty/test ....................... ok
 lost_reset/test ...................... ok
 netfilter_pkt/test ................... ok
 signal/test .......................... ok
 syscalls_file/test ................... ok
 syscall_module/test .................. ok
 syscall_socketcall/test .............. ok
 time_change/test ..................... ok
 user_msg/test ........................ ok
 All tests successful.
 Result: PASS

Changes in v3:
- Make the series bisectable, as requested by Will Deacon. Rather
  than changing __audit_syscall_entry()'s signature in place (which
  broke the build between the core patch and the per-arch conversions),
  patch 1 now adds audit_syscall_entry_regs()/__audit_syscall_entry_regs()
  alongside the existing helpers. The per-arch patches switch to the new
  helpers, and the final patch removes the legacy helpers and renames
  the new ones back to audit_syscall_entry().
- Drop the alpha conversion patch. Per Magnus Lindholm, alpha is
  being moved onto the generic entry framework, which removes its
  private syscall_trace_enter() and routes syscall auditing through
  syscall_enter_audit(); no alpha-specific change is needed once that
  series lands. This series should therefore be applied on top of it.
- Add "parisc: mask compat syscall arguments in syscall_get_arguments()"
  (new patch 8). Moving argument retrieval into syscall_get_arguments()
  would otherwise drop the low-32-bit masking parisc previously did
  inline in its compat audit path, exposing the upper 32 bits of the
  argument registers to audit (and seccomp) for 32-bit tasks. Mask in
  the helper instead, before the parisc conversion, so the series stays
  correct and bisectable.

Changes in v2:
- Rework the core change per Will Deacon's suggestion: instead of
  plumbing all six arguments through every architecture's syscall
  entry path, __audit_syscall_entry() now takes a struct pt_regs *
  and retrieves the arguments itself via syscall_get_arguments().
- Per-arch patches now simply pass regs instead of the individual
  argument registers.
- Fetch the arguments directly into context->argv, dropping the
  temporary array.

Ricardo Robaina (14):
  audit: log all six syscall arguments in the SYSCALL record
  arm: pass pt_regs to audit_syscall_entry()
  arm64: pass pt_regs to audit_syscall_entry()
  csky: pass pt_regs to audit_syscall_entry()
  microblaze: pass pt_regs to audit_syscall_entry()
  mips: pass pt_regs to audit_syscall_entry()
  openrisc: pass pt_regs to audit_syscall_entry()
  parisc: mask compat syscall arguments in syscall_get_arguments()
  parisc: pass pt_regs to audit_syscall_entry()
  sh: pass pt_regs to audit_syscall_entry()
  sparc64: pass pt_regs to audit_syscall_entry()
  um: pass pt_regs to audit_syscall_entry()
  xtensa: pass pt_regs to audit_syscall_entry()
  audit: rename audit_syscall_entry_regs() to audit_syscall_entry()

 arch/arm/kernel/ptrace.c          |  3 +--
 arch/arm64/kernel/ptrace.c        |  3 +--
 arch/csky/kernel/ptrace.c         |  2 +-
 arch/microblaze/kernel/ptrace.c   |  2 +-
 arch/mips/kernel/ptrace.c         |  4 +---
 arch/openrisc/kernel/ptrace.c     |  3 +--
 arch/parisc/include/asm/syscall.h | 18 ++++++++++++------
 arch/parisc/kernel/ptrace.c       |  9 ++-------
 arch/sh/kernel/ptrace_32.c        |  3 +--
 arch/sparc/kernel/ptrace_64.c     |  4 +---
 arch/um/kernel/ptrace.c           |  6 +-----
 arch/xtensa/kernel/ptrace.c       |  4 +---
 include/linux/audit.h             | 13 ++++---------
 include/uapi/linux/audit.h        |  2 ++
 kernel/audit.h                    |  2 +-
 kernel/auditfilter.c              |  2 ++
 kernel/auditsc.c                  | 19 ++++++++-----------
 kernel/entry/syscall-common.c     |  4 +---
 18 files changed, 42 insertions(+), 61 deletions(-)

-- 
2.55.0




More information about the linux-arm-kernel mailing list