| From c8ef44a825d2f8d4e02d1d9f16082ff1defeaf15 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 10 Oct 2018 16:22:57 -0400 |
| Subject: audit: print empty EXECVE args |
| |
| From: Richard Guy Briggs <rgb@redhat.com> |
| |
| [ Upstream commit ea956d8be91edc702a98b7fe1f9463e7ca8c42ab ] |
| |
| Empty executable arguments were being skipped when printing out the list |
| of arguments in an EXECVE record, making it appear they were somehow |
| lost. Include empty arguments as an itemized empty string. |
| |
| Reproducer: |
| autrace /bin/ls "" "/etc" |
| ausearch --start recent -m execve -i | grep EXECVE |
| type=EXECVE msg=audit(10/03/2018 13:04:03.208:1391) : argc=3 a0=/bin/ls a2=/etc |
| |
| With fix: |
| type=EXECVE msg=audit(10/03/2018 21:51:38.290:194) : argc=3 a0=/bin/ls a1= a2=/etc |
| type=EXECVE msg=audit(1538617898.290:194): argc=3 a0="/bin/ls" a1="" a2="/etc" |
| |
| Passes audit-testsuite. GH issue tracker at |
| https://github.com/linux-audit/audit-kernel/issues/99 |
| |
| Signed-off-by: Richard Guy Briggs <rgb@redhat.com> |
| [PM: cleaned up the commit metadata] |
| Signed-off-by: Paul Moore <paul@paul-moore.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| kernel/auditsc.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/kernel/auditsc.c b/kernel/auditsc.c |
| index c2aaf539728fb..854e90be1a023 100644 |
| --- a/kernel/auditsc.c |
| +++ b/kernel/auditsc.c |
| @@ -1096,7 +1096,7 @@ static void audit_log_execve_info(struct audit_context *context, |
| } |
| |
| /* write as much as we can to the audit log */ |
| - if (len_buf > 0) { |
| + if (len_buf >= 0) { |
| /* NOTE: some magic numbers here - basically if we |
| * can't fit a reasonable amount of data into the |
| * existing audit buffer, flush it and start with |
| -- |
| 2.20.1 |
| |