[PATCH 1/2] audit: add execveat to syscall classification

David Drysdale drysdale at google.com
Fri Mar 6 15:40:37 UTC 2015


New execveat syscall from v3.19 is missing from
audit_classify_compat_syscall().

Reported-by: Brian Gerst <brgerst at gmail.com>
Signed-off-by: David Drysdale <drysdale at google.com>
---
 lib/compat_audit.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/lib/compat_audit.c b/lib/compat_audit.c
index 873f75b640ab..a49469f0511d 100644
--- a/lib/compat_audit.c
+++ b/lib/compat_audit.c
@@ -42,6 +42,9 @@ int audit_classify_compat_syscall(int abi, unsigned syscall)
 	case __NR_socketcall:
 		return 4;
 #endif
+#ifdef __NR_execveat
+	case __NR_execveat:
+#endif
 	case __NR_execve:
 		return 5;
 	default:
-- 
1.9.1




More information about the Linux-audit mailing list