@@ -56,11 +56,27 @@ translation, then lets the host kernel (≥ 6.6 has 452) perform the chmod. Conc
5656existing proot build patch (` tools/proot-builder/build_static.sh:118 ` — the ` # --- PROOT PATCH --- `
5757block that already sed-patches ` packages/proot/build.sh ` ):
5858
59- - add ` fchmodat2 ` to ` src/syscall/sysnums.list ` , and
60- - route 452 through the same path-translation case as ` fchmodat ` in the syscall enter handler.
61-
62- ` termux/proot ` master does ** not** carry 452 (verified: ` sysnums.list ` lists only ` SYSNUM(fchmodat) ` ),
63- so this is a ** patch, not a version bump** — bumping ` PROOT_VER ` (` build_static.sh:99 ` ) would not help.
59+ - add ` fchmodat2 ` to ` src/syscall/sysnums.list ` (defines ` PR_fchmodat2 ` ),
60+ - add ` [ 452 ] = PR_fchmodat2 ` to every per-arch table (` src/syscall/sysnums-*.h ` ) so the raw syscall
61+ number maps to the enum,
62+ - route ` PR_fchmodat2 ` through the same path-translation case as ` PR_fchmodat ` in the enter handler
63+ (` enter.c ` ), and
64+ - ** add ` { PR_fchmodat2, 0 } ` to ` proot_sysnums[] ` in ` src/syscall/seccomp.c ` .**
65+
66+ That last step is the one that actually makes it work, and the one first missed. proot does not
67+ ptrace-trap every syscall on a modern host: it installs a seccomp BPF filter that returns
68+ ` SECCOMP_RET_TRACE ` only for the syscalls enumerated in the curated ` proot_sysnums[] ` list (plus
69+ extensions). A syscall absent from that list is never intercepted, so the sysnum table and the
70+ ` enter.c ` case are inert for it. The list already carried ` faccessat2 ` and ` fchmodat ` but not
71+ ` fchmodat2 ` ; without the ` proot_sysnums[] ` entry, 452 passed straight through to the host and the
72+ directory-mode restore still failed. This was reproduced exactly: a first build carrying only the
73+ table + ` enter.c ` edits (release ` binaries-2026-09-01_03-22 ` ) validated with the identical HOLD on a
74+ seccomp-accelerated ` ubuntu-24.04-arm ` host; adding the ` proot_sysnums[] ` entry
75+ (release ` binaries-2026-09-01_11-20 ` ) produced a CLEAN validation.
76+
77+ ` termux/proot ` (pinned v5.1.107.92) does ** not** carry 452 (verified: ` sysnums.list ` lists only
78+ ` SYSNUM(fchmodat) ` ), so this is a ** patch, not a version bump** — bumping ` PROOT_VER `
79+ (` build_static.sh:99 ` ) would not help.
6480
6581This one change makes ` tar ` / ` cp ` / ` rsync ` work ** unmodified** , on the device and on any build host,
6682old or new. It ** collapses the pre/post-` fchmodat2 ` distinction** rather than encoding it in the
0 commit comments