{
    "mode": "man",
    "parameter": "ausyscall",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/ausyscall/8/json",
    "generated": "2026-10-08T07:31:17Z",
    "synopsis": "",
    "sections": {
        "NAME": {
            "content": "ausyscall - a program that allows mapping syscall names and numbers\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "",
            "subsections": [
                {
                    "name": "ausyscall [arch] name | number | --dump | --exact",
                    "content": ""
                }
            ]
        },
        "DESCRIPTION": {
            "content": "ausyscall  is  a  program that prints out the mapping from syscall name to number and reverse\nfor the given arch. The arch can be anything returned by `uname -m`. If arch  is  not  given,\nthe  program  will  take a guess based on the running image. Or for convenience, you can pass\nb32 or b64 to use the current arch but a specific ABI. You may give the syscall name or  num‐\nber  and it will find the opposite. You can also dump the whole table with the --dump option.\nBy default a syscall name lookup will be a substring match meaning that it will try to  match\nall  occurrences  of  the given name with syscalls. So giving a name of chown will match both\nfchown and chown as any other syscall with chown in its name. If this  behavior  is  not  de‐\nsired, pass the --exact flag and it will do an exact string match.\n\nThe program takes the special arch, uring, to denote that you want to specify iouring opera‐\ntions.  In  this case, the arch must be given because it will otherwise detect the underlying\nharware.\n\nThis program can be used to verify syscall numbers on a biarch platform  for  rule  optimiza‐\ntion. For example, suppose you had an auditctl rule:\n",
            "subsections": [
                {
                    "name": "-a always, exit -S open -F exit=-EPERM -k fail-open",
                    "content": "If  you  wanted  to  verify that both 32 and 64 bit programs would be audited, run \"ausyscall\ni386 open\" and then \"ausyscall x8664 open\". (Or use the b32 and b64 option.) Look at the re‐\nturned numbers. If they are different, you will have to write two auditctl rules to get  com‐\nplete coverage.\n",
                    "flag": "-k"
                },
                {
                    "name": "-a always,exit -F arch=b32 -S open -F exit=-EPERM -k fail-open",
                    "content": "",
                    "flag": "-k"
                },
                {
                    "name": "-a always,exit -F arch=b64 -S open -F exit=-EPERM -k fail-open",
                    "content": "For  more  information about a specific syscall, use the man program and pass the number 2 as\nan argument to make sure that you get the syscall information rather than a shell script pro‐\ngram or glibc function call of the same name. For example, if you wanted to learn  about  the\nopen syscall, type: man 2 open.\n",
                    "flag": "-k"
                }
            ]
        },
        "OPTIONS": {
            "content": "--dump Print all syscalls for the given arch\n",
            "subsections": [
                {
                    "name": "--exact",
                    "content": "Instead of doing a partial word match, match the given syscall name exactly.\n\n",
                    "long": "--exact"
                }
            ]
        },
        "SEE ALSO": {
            "content": "ausearch(8), auditctl(8).\n\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "Steve Grubb\n\nRed Hat                                       Feb 2023                                  AUSYSCALL(8)",
            "subsections": []
        }
    },
    "summary": "ausyscall - a program that allows mapping syscall names and numbers",
    "flags": [
        {
            "flag": "",
            "long": "--exact",
            "arg": null,
            "description": "Instead of doing a partial word match, match the given syscall name exactly."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "ausearch",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ausearch/8/json"
        },
        {
            "name": "auditctl",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/auditctl/8/json"
        }
    ]
}