[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20251124194930.8576-1-jeff@bencteux.fr>
Date: Mon, 24 Nov 2025 20:49:30 +0100
From: Jeffrey Bencteux <jeff@...cteux.fr>
To: audit@...r.kernel.org,
paul@...l-moore.com,
eparis@...hat.com
Cc: linux-kernel@...r.kernel.org
Subject: [PATCH] audit: add fchmodat2() to change attributes class
fchmodat2(), introduced in version 6.6 is currently not in the change
attribute class of audit. Calling fchmodat2() to change a file
attribute in the same fashion than chmod() or fchmodat() will bypass
audit rules such as:
-w /tmp/test -p rwa -k test_rwa
The current patch adds fchmodat2() to the change attributes class.
Signed-off-by: Jeffrey Bencteux <jeff@...cteux.fr>
---
include/asm-generic/audit_change_attr.h | 3 +++
1 file changed, 3 insertions(+)
diff --git a/include/asm-generic/audit_change_attr.h b/include/asm-generic/audit_change_attr.h
index cc840537885f..ddd90bbe40df 100644
--- a/include/asm-generic/audit_change_attr.h
+++ b/include/asm-generic/audit_change_attr.h
@@ -26,6 +26,9 @@ __NR_fremovexattr,
__NR_fchownat,
__NR_fchmodat,
#endif
+#ifdef __NR_fchmodat2
+__NR_fchmodat2,
+#endif
#ifdef __NR_chown32
__NR_chown32,
__NR_fchown32,
base-commit: ac3fd01e4c1efce8f2c054cdeb2ddd2fc0fb150d
--
2.49.0
Powered by blists - more mailing lists