[PATCH] apparmor: resolve pivotroot paths before the failure audit

Adriano Cordova adrianox at gmail.com
Mon Sep 28 19:06:20 UTC 2026


build_pivotroot() stores the new and old path names in the audit data
while it mediates a transition, but it returns early for unconfined
profiles and profiles that do not mediate mounts.  Resolve the names in
the failure path in that case before the audit record is emitted.

Signed-off-by: Adriano Cordova <adrianox at gmail.com>
---
 security/apparmor/mount.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/security/apparmor/mount.c b/security/apparmor/mount.c
index 4ed7b9136beb..cd869a07335b 100644
--- a/security/apparmor/mount.c
+++ b/security/apparmor/mount.c
@@ -698,9 +698,18 @@ int aa_pivotroot(const struct cred *subj_cred, struct aa_label *label,
 	return error;
 
 fail:
-	/* TODO: add back in auditing of new_name and old_name,
-	 * needs lifting of name lookup out of profile cb
-	 */
+	if (!ad.name) {
+		struct aa_profile *p = labels_profile(label);
+
+		aa_path_name(new_path, path_flags(p, new_path), new_buffer,
+			     &ad.name, &ad.info, p->disconnected);
+	}
+	if (!ad.mnt.src_name) {
+		struct aa_profile *p = labels_profile(label);
+
+		aa_path_name(old_path, path_flags(p, old_path), old_buffer,
+			     &ad.mnt.src_name, &ad.info, p->disconnected);
+	}
 	ad.mnt.trans = target->hname;
 	error = aa_audit_perm_error(label, AA_MAY_PIVOTROOT, error, &ad,
 				    audit_cb);
-- 
2.51.0




More information about the Linux-security-module-archive mailing list