summaryrefslogtreecommitdiff
path: root/kernel/entry
diff options
context:
space:
mode:
authorThomas Gleixner <tglx@kernel.org>2026-07-12 23:25:17 +0200
committerThomas Gleixner <tglx@kernel.org>2026-07-20 20:38:40 +0200
commit6f25517010ddd3f8080d7e06b9b1cb1b64b73772 (patch)
tree5a2193982f1a0fa79fe46ddcfd72c5e9a169285a /kernel/entry
parent8383e05af734355ba5cdd348991eaa71f6003e71 (diff)
entry: Rework syscall_audit_enter()
Move it out of line and let it reread the syscall number on it's own. That makes the low level entry code denser and allows to move the reread to the call site of syscall_trace_enter() once the tracer is fixed up. To prevent the compiler from putting audit_context() out of line and thereby breaking dead code elimination, mark audit_context() __always_inline. Signed-off-by: Thomas Gleixner <tglx@kernel.org> Tested-by: Michal Suchánek <msuchanek@suse.de> Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com> Link: https://patch.msgid.link/20260712141346.576865340@kernel.org
Diffstat (limited to 'kernel/entry')
-rw-r--r--kernel/entry/syscall-common.c12
1 files changed, 12 insertions, 0 deletions
diff --git a/kernel/entry/syscall-common.c b/kernel/entry/syscall-common.c
index cd4967a9c53e..b3cde6fcee3e 100644
--- a/kernel/entry/syscall-common.c
+++ b/kernel/entry/syscall-common.c
@@ -1,5 +1,6 @@
// SPDX-License-Identifier: GPL-2.0
+#include <linux/audit.h>
#include <linux/entry-common.h>
#define CREATE_TRACE_POINTS
@@ -21,3 +22,14 @@ void trace_syscall_exit(struct pt_regs *regs, long ret)
{
trace_sys_exit(regs, ret);
}
+
+#ifdef CONFIG_AUDITSYSCALL
+void syscall_enter_audit(struct pt_regs *regs)
+{
+ long syscall = syscall_get_nr(current, regs);
+ unsigned long args[6];
+
+ syscall_get_arguments(current, regs, args);
+ __audit_syscall_entry(syscall, args[0], args[1], args[2], args[3]);
+}
+#endif