Hello, this series addresses the problems I have identified when trying to understand how exactly is kernel/audit_tree.c using generic fsnotify framework. I hope I have understood all the interactions right but careful review is certainly welcome (CCing Al as he was the one implementing this code originally). The patches have been tested by a stress test I have written which mounts & unmounts filesystems in the directory tree while adding and removing audit rules for this tree in parallel and accessing the tree to generate events. Still some real-world testing would be welcome. Honza