aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyle Evans <kevans@FreeBSD.org>2026-06-25 17:02:47 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-30 17:00:23 +0000
commitbcbbee810fc9733da27b31b23baeaa2e1af53232 (patch)
treedbd2739b27100fec982ad7ca0305961909bfd1e7
parent1bad1d8c14cdff127d97accd49b0e6da22501b99 (diff)
kern: fix auditing of ptrace(2) syscall requests
`error` here is the return value of syscall_thread_enter() rather than the syscall itself, so the committed audit records do not reflect reality. This is less harmful than them recording an error when the operation actually succeeded, but it could still possibly be used to throw off IDS techniques with things like bsmtrace. Approved by: so Security: FreeBSD-SA-26:45.audit Security: CVE-2026-49426 Reviewed by: des, kib, markj, csjp Differential Revision: https://reviews.freebsd.org/D57847
-rw-r--r--sys/kern/kern_sig.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/sys/kern/kern_sig.c b/sys/kern/kern_sig.c
index e48997ed966a..fed5b62ee1c7 100644
--- a/sys/kern/kern_sig.c
+++ b/sys/kern/kern_sig.c
@@ -2766,7 +2766,7 @@ ptrace_syscallreq(struct thread *td, struct proc *p,
td->td_errno = nerror;
if (audited)
- AUDIT_SYSCALL_EXIT(error, td);
+ AUDIT_SYSCALL_EXIT(tsr->ts_ret.sr_error, td);
if (!sy_thr_static)
syscall_thread_exit(td, se);
}