[PATCH] audit: add fchmodat2() to change attributes class

Jeffrey Bencteux posted 1 patch 2 months, 2 weeks ago
include/asm-generic/audit_change_attr.h | 3 +++
1 file changed, 3 insertions(+)
[PATCH] audit: add fchmodat2() to change attributes class
Posted by Jeffrey Bencteux 2 months, 2 weeks ago
fchmodat2(), introduced in version 6.6 is currently not in the change
attribute class of audit. Calling fchmodat2() to change a file
attribute in the same fashion than chmod() or fchmodat() will bypass
audit rules such as:

-w /tmp/test -p rwa -k test_rwa

The current patch adds fchmodat2() to the change attributes class.

Signed-off-by: Jeffrey Bencteux <jeff@bencteux.fr>
---
 include/asm-generic/audit_change_attr.h | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/include/asm-generic/audit_change_attr.h b/include/asm-generic/audit_change_attr.h
index cc840537885f..ddd90bbe40df 100644
--- a/include/asm-generic/audit_change_attr.h
+++ b/include/asm-generic/audit_change_attr.h
@@ -26,6 +26,9 @@ __NR_fremovexattr,
 __NR_fchownat,
 __NR_fchmodat,
 #endif
+#ifdef __NR_fchmodat2
+__NR_fchmodat2,
+#endif
 #ifdef __NR_chown32
 __NR_chown32,
 __NR_fchown32,

base-commit: ac3fd01e4c1efce8f2c054cdeb2ddd2fc0fb150d
-- 
2.49.0
Re: [PATCH] audit: add fchmodat2() to change attributes class
Posted by Paul Moore 1 month, 3 weeks ago
On Nov 24, 2025 Jeffrey Bencteux <jeff@bencteux.fr> wrote:
> 
> fchmodat2(), introduced in version 6.6 is currently not in the change
> attribute class of audit. Calling fchmodat2() to change a file
> attribute in the same fashion than chmod() or fchmodat() will bypass
> audit rules such as:
> 
> -w /tmp/test -p rwa -k test_rwa
> 
> The current patch adds fchmodat2() to the change attributes class.
> 
> Signed-off-by: Jeffrey Bencteux <jeff@bencteux.fr>
> ---
>  include/asm-generic/audit_change_attr.h | 3 +++
>  1 file changed, 3 insertions(+)

Merged into audit/dev, thanks.

--
paul-moore.com