summaryrefslogtreecommitdiff
path: root/kernel
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-08-19 16:21:32 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-08-19 16:21:32 -0700
commit83453b6f5131a83af7b2a4df28bc776353ac56c5 (patch)
tree88c1aa2a799b8aea425fe5e084a97f4cfb22a18a /kernel
parentcb8a75eec0877810b50aa1c5a833f929525cd2ee (diff)
parent783f0f0974c156aca630f4ffff248671082a098d (diff)
downloadlwn-83453b6f5131a83af7b2a4df28bc776353ac56c5.tar.gz
lwn-83453b6f5131a83af7b2a4df28bc776353ac56c5.zip
Merge tag 'audit-pr-20260814' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit
Pull audit updates from Paul Moore: - Drop BUG_ON() assertions from two functions While I don't recall any bug reports from either of these assertions in recent memory, neither of these checks warrant the kernel panic that could result from BUG_ON(). One of the BUG_ON() calls is converted to a WARN_ON_ONCE() and the other to a lockdep assertion. - Fix an audit tree reference counting problem Fix a corner case where audit could end up unintentionally dropping the last reference to an audit tree while the tree was still in use. We should probably revisit the audit tree handling code in full, but this patch works, and should be easy to backport to stable trees and downstream kernels. - Update the audit syscall classification tables Add some missing syscalls to the PERM class * tag 'audit-pr-20260814' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit: audit: avoid dropping live tree ref on fsnotify rule autoremove audit: drop BUG_ON() from audit_signal_info_syscall() audit: drop BUG_ON() from audit_add_to_parent() audit: add missing syscalls to PERM class tables
Diffstat (limited to 'kernel')
-rw-r--r--kernel/audit_watch.c2
-rw-r--r--kernel/auditfilter.c6
-rw-r--r--kernel/auditsc.c3
3 files changed, 5 insertions, 6 deletions
diff --git a/kernel/audit_watch.c b/kernel/audit_watch.c
index 06dd0ebe73e2..4ac8a91e9ba8 100644
--- a/kernel/audit_watch.c
+++ b/kernel/audit_watch.c
@@ -372,7 +372,7 @@ static void audit_add_to_parent(struct audit_krule *krule,
struct audit_watch *w, *watch = krule->watch;
int watch_found = 0;
- BUG_ON(!mutex_is_locked(&audit_filter_mutex));
+ lockdep_assert_held(&audit_filter_mutex);
list_for_each_entry(w, &parent->watches, wlist) {
if (strcmp(watch->path, w->path))
diff --git a/kernel/auditfilter.c b/kernel/auditfilter.c
index 7f791afe5791..f52645625214 100644
--- a/kernel/auditfilter.c
+++ b/kernel/auditfilter.c
@@ -1023,7 +1023,6 @@ static inline int audit_add_rule(struct audit_entry *entry)
int audit_del_rule(struct audit_entry *entry)
{
struct audit_entry *e;
- struct audit_tree *tree = entry->rule.tree;
struct list_head *list;
int ret = 0;
#ifdef CONFIG_AUDITSYSCALL
@@ -1071,9 +1070,6 @@ int audit_del_rule(struct audit_entry *entry)
out:
mutex_unlock(&audit_filter_mutex);
- if (tree)
- audit_put_tree(tree); /* that's the temporary one */
-
return ret;
}
@@ -1158,6 +1154,8 @@ int audit_rule_change(int type, int seq, void *data, size_t datasz)
}
if (err || type == AUDIT_DEL_RULE) {
+ if (type == AUDIT_DEL_RULE && entry->rule.tree)
+ audit_put_tree(entry->rule.tree);
if (entry->rule.exe)
audit_remove_mark(entry->rule.exe);
audit_free_rule(entry);
diff --git a/kernel/auditsc.c b/kernel/auditsc.c
index 6610e667c728..2b9ce0b52511 100644
--- a/kernel/auditsc.c
+++ b/kernel/auditsc.c
@@ -2712,7 +2712,8 @@ int audit_signal_info_syscall(struct task_struct *t)
axp->d.next = ctx->aux_pids;
ctx->aux_pids = (void *)axp;
}
- BUG_ON(axp->pid_count >= AUDIT_AUX_PIDS);
+ if (WARN_ON_ONCE(axp->pid_count >= AUDIT_AUX_PIDS))
+ return -EINVAL;
axp->target_pid[axp->pid_count] = task_tgid_nr(t);
axp->target_auid[axp->pid_count] = audit_get_loginuid(t);