[PATCH v3 00/14] audit: log all six syscall arguments in the SYSCALL record
Ricardo Robaina
rrobaina at redhat.com
Tue Sep 22 12:19:52 PDT 2026
The SYSCALL record currently logs only four of the six syscall
arguments (a0-a3), silently discarding the remaining two. This
leads to the need for auxiliary records when audit-relevant
data lands in the 5th or 6th argument of a syscall.
This series extends the SYSCALL record to log all six arguments,
by adding arguments a4 and a5 inline within the existing record.
Rather than plumbing two more argument registers through every
architecture's syscall entry path, audit_syscall_entry() now takes a
struct pt_regs * and retrieves all six arguments itself via
syscall_get_arguments(); the per-arch patches simply pass regs. The two
new arguments are also wired into the audit filter, so rules can match
on a4 and a5.
To keep the series bisectable, the new pt_regs-based helpers are added
first (patch 1), each architecture is converted one per patch, and the
final patch removes the legacy argument-register helpers and renames the
new ones back to audit_syscall_entry(). Every commit builds on its own.
The audit testsuite runs successfully:
# make test
make -C tests test
Running as user root
with context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
on system Fedora
amcast_joinpart/test ................. ok
backlog_wait_time_actual_reset/test .. ok
bpf/test ............................. ok
coredump/test ........................ ok
exec_execve/test ..................... ok
exec_name/test ....................... ok
fanotify/test ........................ ok
field_compare/test ................... ok
file_create/test ..................... ok
file_delete/test ..................... ok
file_permission/test ................. ok
file_rename/test ..................... ok
filter_device/test ................... ok
filter_exclude/test .................. ok
filter_exit/test ..................... ok
filter_inode/test .................... ok
filter_saddr_fam/test ................ ok
filter_sessionid/test ................ ok
io_uring/test ........................ ok
login_tty/test ....................... ok
lost_reset/test ...................... ok
netfilter_pkt/test ................... ok
signal/test .......................... ok
syscalls_file/test ................... ok
syscall_module/test .................. ok
syscall_socketcall/test .............. ok
time_change/test ..................... ok
user_msg/test ........................ ok
All tests successful.
Result: PASS
Changes in v3:
- Make the series bisectable, as requested by Will Deacon. Rather
than changing __audit_syscall_entry()'s signature in place (which
broke the build between the core patch and the per-arch conversions),
patch 1 now adds audit_syscall_entry_regs()/__audit_syscall_entry_regs()
alongside the existing helpers. The per-arch patches switch to the new
helpers, and the final patch removes the legacy helpers and renames
the new ones back to audit_syscall_entry().
- Drop the alpha conversion patch. Per Magnus Lindholm, alpha is
being moved onto the generic entry framework, which removes its
private syscall_trace_enter() and routes syscall auditing through
syscall_enter_audit(); no alpha-specific change is needed once that
series lands. This series should therefore be applied on top of it.
- Add "parisc: mask compat syscall arguments in syscall_get_arguments()"
(new patch 8). Moving argument retrieval into syscall_get_arguments()
would otherwise drop the low-32-bit masking parisc previously did
inline in its compat audit path, exposing the upper 32 bits of the
argument registers to audit (and seccomp) for 32-bit tasks. Mask in
the helper instead, before the parisc conversion, so the series stays
correct and bisectable.
Changes in v2:
- Rework the core change per Will Deacon's suggestion: instead of
plumbing all six arguments through every architecture's syscall
entry path, __audit_syscall_entry() now takes a struct pt_regs *
and retrieves the arguments itself via syscall_get_arguments().
- Per-arch patches now simply pass regs instead of the individual
argument registers.
- Fetch the arguments directly into context->argv, dropping the
temporary array.
Ricardo Robaina (14):
audit: log all six syscall arguments in the SYSCALL record
arm: pass pt_regs to audit_syscall_entry()
arm64: pass pt_regs to audit_syscall_entry()
csky: pass pt_regs to audit_syscall_entry()
microblaze: pass pt_regs to audit_syscall_entry()
mips: pass pt_regs to audit_syscall_entry()
openrisc: pass pt_regs to audit_syscall_entry()
parisc: mask compat syscall arguments in syscall_get_arguments()
parisc: pass pt_regs to audit_syscall_entry()
sh: pass pt_regs to audit_syscall_entry()
sparc64: pass pt_regs to audit_syscall_entry()
um: pass pt_regs to audit_syscall_entry()
xtensa: pass pt_regs to audit_syscall_entry()
audit: rename audit_syscall_entry_regs() to audit_syscall_entry()
arch/arm/kernel/ptrace.c | 3 +--
arch/arm64/kernel/ptrace.c | 3 +--
arch/csky/kernel/ptrace.c | 2 +-
arch/microblaze/kernel/ptrace.c | 2 +-
arch/mips/kernel/ptrace.c | 4 +---
arch/openrisc/kernel/ptrace.c | 3 +--
arch/parisc/include/asm/syscall.h | 18 ++++++++++++------
arch/parisc/kernel/ptrace.c | 9 ++-------
arch/sh/kernel/ptrace_32.c | 3 +--
arch/sparc/kernel/ptrace_64.c | 4 +---
arch/um/kernel/ptrace.c | 6 +-----
arch/xtensa/kernel/ptrace.c | 4 +---
include/linux/audit.h | 13 ++++---------
include/uapi/linux/audit.h | 2 ++
kernel/audit.h | 2 +-
kernel/auditfilter.c | 2 ++
kernel/auditsc.c | 19 ++++++++-----------
kernel/entry/syscall-common.c | 4 +---
18 files changed, 42 insertions(+), 61 deletions(-)
--
2.55.0
More information about the linux-arm-kernel
mailing list