* [PATCH v3 0/2] integrity: Return error codes in audit messages
@ 2026-09-16 21:36 Frederick Lawler
2026-09-16 21:36 ` [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites Frederick Lawler
2026-09-16 21:36 ` [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg() Frederick Lawler
0 siblings, 2 replies; 7+ messages in thread
From: Frederick Lawler @ 2026-09-16 21:36 UTC (permalink / raw)
To: Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg,
Paul Moore, James Morris, Serge E. Hallyn
Cc: linux-integrity, linux-security-module, linux-kernel, kernel-team,
Frederick Lawler
Commit 2f845882ecd2 ("integrity: Add errno field in audit message")
introduced an audit log function that can take an error code. It is
wrapped by integrity_audit_msg() that implicitly sets the error code
argument to zero. The problem is that there are uses of integrity_audit_msg()
such as ima_collect_measurement() that hide the failure cause for
the message.
This series aims to clarify error reasons for failures, and then expose
error codes based on the following criteria:
1. The log depends on a result from earlier callee, and/or
2. The caller function itself returns with that result
ima_release_policy() is the only caller I thought made sense to keep as
is. The message doesn't correlate with a return code, nor does it
depend on a result from an earlier callee in the function.
Signed-off-by: Frederick Lawler <fred@cloudflare.com>
---
Changes in v3:
- Condense series to two commits.
- Reduce review churn by adding error code to integrity_audit_msg().
- ima_write_policy() to report -EINVAL instead of result.
- Link to v2: https://lore.kernel.org/r/20260727-report-hash-error-v2-0-30e394f524fc@cloudflare.com
Changes in v2:
- Changes from v1 are now reflected in patch 3.
- Replace all instances of integrity_audit_msg().
- Convert to patch series.
- Link to v1: https://lore.kernel.org/r/20260716-report-hash-error-v1-1-ac19281112e4@cloudflare.com
---
Frederick Lawler (2):
integrity: Report error code in integrity_audit_msg() call sites
integrity: Replace integrity_audit_message() with integrity_audit_msg()
security/integrity/evm/evm_main.c | 9 +++++----
security/integrity/ima/ima_api.c | 8 ++++----
security/integrity/ima/ima_appraise.c | 6 +++---
security/integrity/ima/ima_fs.c | 4 ++--
security/integrity/ima/ima_init.c | 2 +-
security/integrity/ima/ima_main.c | 13 +++++++------
security/integrity/ima/ima_policy.c | 11 ++++++-----
security/integrity/ima/ima_queue.c | 2 +-
security/integrity/ima/ima_queue_keys.c | 8 ++++----
security/integrity/ima/ima_template_lib.c | 2 +-
security/integrity/integrity.h | 18 +++---------------
security/integrity/integrity_audit.c | 12 ++----------
12 files changed, 39 insertions(+), 56 deletions(-)
---
base-commit: 6903878d4654bdef4e08e38cdf1ae306ce7de5f9
change-id: 20260716-report-hash-error-5203d6fe6e4e
Best regards,
--
Frederick Lawler <fred@cloudflare.com>
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
2026-09-16 21:36 [PATCH v3 0/2] integrity: Return error codes in audit messages Frederick Lawler
@ 2026-09-16 21:36 ` Frederick Lawler
2026-09-17 22:58 ` Enrico Bravi
2026-09-16 21:36 ` [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg() Frederick Lawler
1 sibling, 1 reply; 7+ messages in thread
From: Frederick Lawler @ 2026-09-16 21:36 UTC (permalink / raw)
To: Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg,
Paul Moore, James Morris, Serge E. Hallyn
Cc: linux-integrity, linux-security-module, linux-kernel, kernel-team,
Frederick Lawler
integrity_audit_msg() hides error codes by wrapping
integrity_audit_message() which obfuscates the underlying reason for the
failure.
Update integrity_audit_msg() call sites to take an error code and report
errors the same as integrity_audit_message().
Signed-off-by: Frederick Lawler <fred@cloudflare.com>
---
security/integrity/evm/evm_main.c | 9 +++++----
security/integrity/ima/ima_api.c | 8 ++++----
security/integrity/ima/ima_appraise.c | 6 +++---
security/integrity/ima/ima_fs.c | 4 ++--
security/integrity/ima/ima_init.c | 2 +-
security/integrity/ima/ima_main.c | 7 ++++---
security/integrity/ima/ima_policy.c | 11 ++++++-----
security/integrity/ima/ima_queue.c | 2 +-
security/integrity/ima/ima_template_lib.c | 2 +-
security/integrity/integrity.h | 5 +++--
security/integrity/integrity_audit.c | 5 +++--
11 files changed, 33 insertions(+), 28 deletions(-)
diff --git a/security/integrity/evm/evm_main.c b/security/integrity/evm/evm_main.c
index b59e3f121b8a89edb14d811351ec393a69de8ff7..5be9349afcd09b47b78d1126ffc1fe341264ae6e 100644
--- a/security/integrity/evm/evm_main.c
+++ b/security/integrity/evm/evm_main.c
@@ -563,7 +563,7 @@ static int evm_protect_xattr(struct mnt_idmap *idmap,
dentry->d_inode, dentry->d_name.name,
"update_metadata",
integrity_status_msg[evm_status],
- -EPERM, 0);
+ -EPERM, 0, -EPERM);
}
out:
/* Exception if the HMAC is not going to be calculated. */
@@ -588,7 +588,7 @@ static int evm_protect_xattr(struct mnt_idmap *idmap,
integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
dentry->d_name.name, "appraise_metadata",
integrity_status_msg[evm_status],
- -EPERM, 0);
+ -EPERM, 0, -EPERM);
return evm_status == INTEGRITY_PASS ? 0 : -EPERM;
}
@@ -729,7 +729,7 @@ static int evm_inode_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
dentry->d_name.name, "appraise_metadata",
integrity_status_msg[evm_status],
- -EPERM, 0);
+ -EPERM, 0, -EPERM);
return -EPERM;
}
@@ -992,7 +992,8 @@ static int evm_inode_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
dentry->d_name.name, "appraise_metadata",
- integrity_status_msg[evm_status], -EPERM, 0);
+ integrity_status_msg[evm_status], -EPERM, 0,
+ -EPERM);
return -EPERM;
}
diff --git a/security/integrity/ima/ima_api.c b/security/integrity/ima/ima_api.c
index 122d127e108dcca8ddae6575c908144859783fb6..f765bfe5db68d0847cfe5b47f81b64018083f65a 100644
--- a/security/integrity/ima/ima_api.c
+++ b/security/integrity/ima/ima_api.c
@@ -116,7 +116,7 @@ int ima_store_template(struct ima_template_entry *entry,
if (result < 0) {
integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode,
template_name, op,
- audit_cause, result, 0);
+ audit_cause, result, 0, result);
return result;
}
}
@@ -159,7 +159,7 @@ void ima_add_violation(struct file *file, const unsigned char *filename,
ima_free_template_entry(entry);
err_out:
integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
- op, cause, result, 0);
+ op, cause, result, 0, result);
}
/**
@@ -330,7 +330,7 @@ int ima_collect_measurement(struct ima_iint_cache *iint, struct file *file,
integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode,
filename.name.name, "collect_data",
- audit_cause, result, 0);
+ audit_cause, result, 0, result);
release_dentry_name_snapshot(&filename);
}
@@ -383,7 +383,7 @@ void ima_store_measurement(struct ima_iint_cache *iint, struct file *file,
result = ima_alloc_init_template(&event_data, &entry, template_desc);
if (result < 0) {
integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
- op, audit_cause, result, 0);
+ op, audit_cause, result, 0, result);
return;
}
diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
index b280488e15fcb0b6f8a8a0caaab93c7d511e4a40..6dc712f430f44ee18c3418a6bf4cd4da49758b98 100644
--- a/security/integrity/ima/ima_appraise.c
+++ b/security/integrity/ima/ima_appraise.c
@@ -564,7 +564,7 @@ int ima_appraise_measurement(enum ima_hooks func, struct ima_iint_cache *iint,
status = INTEGRITY_FAIL;
cause = "unverifiable-signature";
integrity_audit_msg(audit_msgno, inode, filename,
- op, cause, rc, 0);
+ op, cause, rc, 0, rc);
} else if (status != INTEGRITY_PASS) {
/* Fix mode, but don't replace file signatures. */
if ((ima_appraise & IMA_APPRAISE_FIX) && !try_modsig &&
@@ -589,7 +589,7 @@ int ima_appraise_measurement(enum ima_hooks func, struct ima_iint_cache *iint,
}
integrity_audit_msg(audit_msgno, inode, filename,
- op, cause, rc, 0);
+ op, cause, rc, 0, rc);
} else {
ima_cache_flags(iint, func);
}
@@ -752,7 +752,7 @@ static int validate_hash_algo(struct dentry *dentry,
path = NULL;
integrity_audit_msg(AUDIT_INTEGRITY_DATA, d_inode(dentry), path,
- "set_data", errmsg, -EACCES, 0);
+ "set_data", errmsg, -EACCES, 0, -EACCES);
kfree(pathbuf);
diff --git a/security/integrity/ima/ima_fs.c b/security/integrity/ima/ima_fs.c
index 2a0bca5543161912abe2a0236c9fcae7055e62bc..6d2ef44b21f8d40b4981a6a441cf7c3d69f94dee 100644
--- a/security/integrity/ima/ima_fs.c
+++ b/security/integrity/ima/ima_fs.c
@@ -595,7 +595,7 @@ static ssize_t ima_write_policy(struct file *file, const char __user *buf,
pr_err("signed policy file (specified as an absolute pathname) required\n");
integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
"policy_update", "signed policy required",
- 1, 0);
+ 1, 0, -EINVAL);
result = -EACCES;
} else {
ima_measure_raw_policy(data, datalen);
@@ -745,7 +745,7 @@ static int ima_release_policy(struct inode *inode, struct file *file)
pr_info("policy update %s\n", cause);
integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
- "policy_update", cause, !valid_policy, 0);
+ "policy_update", cause, !valid_policy, 0, 0);
if (!valid_policy) {
ima_delete_rules();
diff --git a/security/integrity/ima/ima_init.c b/security/integrity/ima/ima_init.c
index d53f4d89a53e56d7ebb31950c10b37fc89782753..7a76e2686267482b10bf854a76829c60ef9f1e1b 100644
--- a/security/integrity/ima/ima_init.c
+++ b/security/integrity/ima/ima_init.c
@@ -103,7 +103,7 @@ static int __init ima_add_boot_aggregate(void)
return 0;
err_out:
integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, filename, op,
- audit_cause, result, 0);
+ audit_cause, result, 0, result);
return result;
}
diff --git a/security/integrity/ima/ima_main.c b/security/integrity/ima/ima_main.c
index ab1e53b3210d3a4d3f91d65f7db19e6a2a2d401c..9e80f40680d7be08d14d26ba48ed334d4e4ab10c 100644
--- a/security/integrity/ima/ima_main.c
+++ b/security/integrity/ima/ima_main.c
@@ -119,7 +119,7 @@ static int mmap_violation_check(enum ima_hooks func, struct file *file,
*pathname = ima_d_path(&file->f_path, pathbuf,
filename);
integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode, *pathname,
- "mmap_file", "mmapped_writers", rc, 0);
+ "mmap_file", "mmapped_writers", rc, 0, rc);
}
return rc;
}
@@ -466,7 +466,7 @@ static int process_measurement(struct file *file, const struct cred *cred,
integrity_audit_msg(AUDIT_INTEGRITY_DATA, file_inode(file),
pathname, "collect_data",
- "denied-hash-algorithm", rc, 0);
+ "denied-hash-algorithm", rc, 0, rc);
}
out_locked:
if ((mask & MAY_WRITE) && test_bit(IMA_DIGSIG, &iint->atomic_flags) &&
@@ -579,7 +579,8 @@ static int ima_file_mprotect(struct vm_area_struct *vma, unsigned long reqprot,
file = vma->vm_file;
pathname = ima_d_path(&file->f_path, &pathbuf, filename);
integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode, pathname,
- "collect_data", "failed-mprotect", result, 0);
+ "collect_data", "failed-mprotect", result, 0,
+ result);
if (pathbuf)
__putname(pathbuf);
diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c
index 68d9a5e6c232ea0678e9f51f105cebecccccb43e..9013c962dc0bfd6184948230ad6746e71f6e82f5 100644
--- a/security/integrity/ima/ima_policy.c
+++ b/security/integrity/ima/ima_policy.c
@@ -1992,7 +1992,8 @@ ssize_t ima_parse_add_rule(char *rule)
entry = kzalloc_obj(*entry);
if (!entry) {
integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL,
- NULL, op, "-ENOMEM", -ENOMEM, audit_info);
+ NULL, op, "-ENOMEM", -ENOMEM, audit_info,
+ -ENOMEM);
return -ENOMEM;
}
@@ -2003,7 +2004,7 @@ ssize_t ima_parse_add_rule(char *rule)
ima_free_rule(entry);
integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL,
NULL, op, "invalid-policy", result,
- audit_info);
+ audit_info, result);
return result;
}
@@ -2421,7 +2422,7 @@ void ima_measure_loaded_policy(void)
rule = kmalloc(rule_len, GFP_KERNEL);
if (!rule) {
integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, event_name,
- op, "ENOMEM", result, 0);
+ op, "ENOMEM", result, 0, result);
return;
}
@@ -2440,7 +2441,7 @@ void ima_measure_loaded_policy(void)
result = -E2BIG;
integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL,
event_name, op, "rule_length",
- result, 0);
+ result, 0, result);
rcu_read_unlock();
goto free_rule;
}
@@ -2454,7 +2455,7 @@ void ima_measure_loaded_policy(void)
file.buf = kmalloc(file_len, GFP_KERNEL);
if (!file.buf) {
integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, event_name,
- op, "ENOMEM", result, 0);
+ op, "ENOMEM", result, 0, result);
goto free_rule;
}
diff --git a/security/integrity/ima/ima_queue.c b/security/integrity/ima/ima_queue.c
index f89f0ca3d4edf16a7147b3c23d25fc2cf18044c6..8d3282ff7da4131ae4389bf832442285e500542d 100644
--- a/security/integrity/ima/ima_queue.c
+++ b/security/integrity/ima/ima_queue.c
@@ -292,7 +292,7 @@ int ima_add_template_entry(struct ima_template_entry *entry, int violation,
out:
mutex_unlock(&ima_extend_list_mutex);
integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
- op, audit_cause, result, audit_info);
+ op, audit_cause, result, audit_info, result);
return result;
}
diff --git a/security/integrity/ima/ima_template_lib.c b/security/integrity/ima/ima_template_lib.c
index 8a89236f926c10af0dd2b2ef08fbe59bd8a78b66..9bd80ca1159a2fe24b3ea3308a118f6beea733cb 100644
--- a/security/integrity/ima/ima_template_lib.c
+++ b/security/integrity/ima/ima_template_lib.c
@@ -392,7 +392,7 @@ int ima_eventdigest_init(struct ima_event_data *event_data,
if (result) {
integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode,
event_data->filename, "collect_data",
- "failed", result, 0);
+ "failed", result, 0, result);
return result;
}
cur_digest = hash_hdr->digest;
diff --git a/security/integrity/integrity.h b/security/integrity/integrity.h
index 0c581c03c5da72d80e9c352a7adff1fb89628644..2ab6b7e34e7ee2dd29ae03ae1fb45fa26d9c032a 100644
--- a/security/integrity/integrity.h
+++ b/security/integrity/integrity.h
@@ -218,7 +218,8 @@ static inline void evm_load_x509(void)
/* declarations */
void integrity_audit_msg(int audit_msgno, struct inode *inode,
const unsigned char *fname, const char *op,
- const char *cause, int result, int info);
+ const char *cause, int result, int info,
+ int errno);
void integrity_audit_message(int audit_msgno, struct inode *inode,
const unsigned char *fname, const char *op,
@@ -235,7 +236,7 @@ integrity_audit_log_start(struct audit_context *ctx, gfp_t gfp_mask, int type)
static inline void integrity_audit_msg(int audit_msgno, struct inode *inode,
const unsigned char *fname,
const char *op, const char *cause,
- int result, int info)
+ int result, int info, int errno)
{
}
diff --git a/security/integrity/integrity_audit.c b/security/integrity/integrity_audit.c
index d8d9e5ff1cd22b091f462d1e83d28d2d6bd983e9..2dd2d7e3916e7bf35c753450315ff22e2d0292b7 100644
--- a/security/integrity/integrity_audit.c
+++ b/security/integrity/integrity_audit.c
@@ -27,10 +27,11 @@ __setup("integrity_audit=", integrity_audit_setup);
void integrity_audit_msg(int audit_msgno, struct inode *inode,
const unsigned char *fname, const char *op,
- const char *cause, int result, int audit_info)
+ const char *cause, int result, int audit_info,
+ int errno)
{
integrity_audit_message(audit_msgno, inode, fname, op, cause,
- result, audit_info, 0);
+ result, audit_info, errno);
}
void integrity_audit_message(int audit_msgno, struct inode *inode,
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
2026-09-16 21:36 [PATCH v3 0/2] integrity: Return error codes in audit messages Frederick Lawler
2026-09-16 21:36 ` [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites Frederick Lawler
@ 2026-09-16 21:36 ` Frederick Lawler
2026-09-18 21:49 ` Mimi Zohar
1 sibling, 1 reply; 7+ messages in thread
From: Frederick Lawler @ 2026-09-16 21:36 UTC (permalink / raw)
To: Mimi Zohar, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg,
Paul Moore, James Morris, Serge E. Hallyn
Cc: linux-integrity, linux-security-module, linux-kernel, kernel-team,
Frederick Lawler
integrity_audit_msg() wraps integrity_audit_message(). Replace remaining
call sites with the truncated function name. Then remove it since there
are no more callers.
Signed-off-by: Frederick Lawler <fred@cloudflare.com>
---
security/integrity/ima/ima_main.c | 6 +++---
security/integrity/ima/ima_queue_keys.c | 8 ++++----
security/integrity/integrity.h | 13 -------------
security/integrity/integrity_audit.c | 9 ---------
4 files changed, 7 insertions(+), 29 deletions(-)
diff --git a/security/integrity/ima/ima_main.c b/security/integrity/ima/ima_main.c
index 9e80f40680d7be08d14d26ba48ed334d4e4ab10c..bd9997b01633d6235fc2fcaa9bef1931d6ba7247 100644
--- a/security/integrity/ima/ima_main.c
+++ b/security/integrity/ima/ima_main.c
@@ -1196,9 +1196,9 @@ int process_buffer_measurement(struct mnt_idmap *idmap,
out:
if (ret < 0)
- integrity_audit_message(AUDIT_INTEGRITY_PCR, NULL, eventname,
- func_measure_str(func),
- audit_cause, ret, 0, ret);
+ integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, eventname,
+ func_measure_str(func),
+ audit_cause, ret, 0, ret);
return ret;
}
diff --git a/security/integrity/ima/ima_queue_keys.c b/security/integrity/ima/ima_queue_keys.c
index b5ed33cbb272fdfaf7f5e945137c56e46e0d7db1..8adc8863ad5a540bf0c047ba47cc4817fcb46e9a 100644
--- a/security/integrity/ima/ima_queue_keys.c
+++ b/security/integrity/ima/ima_queue_keys.c
@@ -90,10 +90,10 @@ static struct ima_key_entry *ima_alloc_key_entry(struct key *keyring,
out:
if (rc) {
- integrity_audit_message(AUDIT_INTEGRITY_PCR, NULL,
- keyring->description,
- func_measure_str(KEY_CHECK),
- audit_cause, rc, 0, rc);
+ integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL,
+ keyring->description,
+ func_measure_str(KEY_CHECK),
+ audit_cause, rc, 0, rc);
ima_free_key_entry(entry);
entry = NULL;
}
diff --git a/security/integrity/integrity.h b/security/integrity/integrity.h
index 2ab6b7e34e7ee2dd29ae03ae1fb45fa26d9c032a..52c5ec881cca468bde72c885cffa1c564877735e 100644
--- a/security/integrity/integrity.h
+++ b/security/integrity/integrity.h
@@ -221,11 +221,6 @@ void integrity_audit_msg(int audit_msgno, struct inode *inode,
const char *cause, int result, int info,
int errno);
-void integrity_audit_message(int audit_msgno, struct inode *inode,
- const unsigned char *fname, const char *op,
- const char *cause, int result, int info,
- int errno);
-
static inline struct audit_buffer *
integrity_audit_log_start(struct audit_context *ctx, gfp_t gfp_mask, int type)
{
@@ -240,14 +235,6 @@ static inline void integrity_audit_msg(int audit_msgno, struct inode *inode,
{
}
-static inline void integrity_audit_message(int audit_msgno,
- struct inode *inode,
- const unsigned char *fname,
- const char *op, const char *cause,
- int result, int info, int errno)
-{
-}
-
static inline struct audit_buffer *
integrity_audit_log_start(struct audit_context *ctx, gfp_t gfp_mask, int type)
{
diff --git a/security/integrity/integrity_audit.c b/security/integrity/integrity_audit.c
index 2dd2d7e3916e7bf35c753450315ff22e2d0292b7..22106aaeb0df21fef0990b80611dcd13cba112be 100644
--- a/security/integrity/integrity_audit.c
+++ b/security/integrity/integrity_audit.c
@@ -29,15 +29,6 @@ void integrity_audit_msg(int audit_msgno, struct inode *inode,
const unsigned char *fname, const char *op,
const char *cause, int result, int audit_info,
int errno)
-{
- integrity_audit_message(audit_msgno, inode, fname, op, cause,
- result, audit_info, errno);
-}
-
-void integrity_audit_message(int audit_msgno, struct inode *inode,
- const unsigned char *fname, const char *op,
- const char *cause, int result, int audit_info,
- int errno)
{
struct audit_buffer *ab;
char name[TASK_COMM_LEN];
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
2026-09-16 21:36 ` [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites Frederick Lawler
@ 2026-09-17 22:58 ` Enrico Bravi
2026-09-18 21:11 ` Frederick Lawler
0 siblings, 1 reply; 7+ messages in thread
From: Enrico Bravi @ 2026-09-17 22:58 UTC (permalink / raw)
To: zohar@linux.ibm.com, roberto.sassu@huawei.com,
eric.snowberg@oracle.com, fred@cloudflare.com,
paul@paul-moore.com, dmitry.kasatkin@gmail.com, serge@hallyn.com,
jmorris@namei.org
Cc: linux-security-module@vger.kernel.org,
linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org,
kernel-team@cloudflare.com
Hi Frederick,
On Wed, 2026-09-16 at 16:36 -0500, Frederick Lawler wrote:
> integrity_audit_msg() hides error codes by wrapping
> integrity_audit_message() which obfuscates the underlying reason for the
> failure.
>
> Update integrity_audit_msg() call sites
here it could be mentioned that also integrity_audit_msg() itself is
updated.
> to take an error code and report
> errors the same as integrity_audit_message().
>
> Signed-off-by: Frederick Lawler <fred@cloudflare.com>
> ---
> security/integrity/evm/evm_main.c | 9 +++++----
> security/integrity/ima/ima_api.c | 8 ++++----
> security/integrity/ima/ima_appraise.c | 6 +++---
> security/integrity/ima/ima_fs.c | 4 ++--
> security/integrity/ima/ima_init.c | 2 +-
> security/integrity/ima/ima_main.c | 7 ++++---
> security/integrity/ima/ima_policy.c | 11 ++++++-----
> security/integrity/ima/ima_queue.c | 2 +-
> security/integrity/ima/ima_template_lib.c | 2 +-
> security/integrity/integrity.h | 5 +++--
> security/integrity/integrity_audit.c | 5 +++--
> 11 files changed, 33 insertions(+), 28 deletions(-)
>
> diff --git a/security/integrity/evm/evm_main.c
> b/security/integrity/evm/evm_main.c
> index
> b59e3f121b8a89edb14d811351ec393a69de8ff7..5be9349afcd09b47b78d1126ffc1fe341264
> ae6e 100644
> --- a/security/integrity/evm/evm_main.c
> +++ b/security/integrity/evm/evm_main.c
> @@ -563,7 +563,7 @@ static int evm_protect_xattr(struct mnt_idmap *idmap,
> dentry->d_inode, dentry->d_name.name,
> "update_metadata",
> integrity_status_msg[evm_status],
> - -EPERM, 0);
> + -EPERM, 0, -EPERM);
> }
> out:
> /* Exception if the HMAC is not going to be calculated. */
> @@ -588,7 +588,7 @@ static int evm_protect_xattr(struct mnt_idmap *idmap,
> integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
> dentry->d_name.name, "appraise_metadata",
> integrity_status_msg[evm_status],
> - -EPERM, 0);
> + -EPERM, 0, -EPERM);
> return evm_status == INTEGRITY_PASS ? 0 : -EPERM;
> }
>
> @@ -729,7 +729,7 @@ static int evm_inode_set_acl(struct mnt_idmap *idmap,
> struct dentry *dentry,
> integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
> dentry->d_name.name, "appraise_metadata",
> integrity_status_msg[evm_status],
> - -EPERM, 0);
> + -EPERM, 0, -EPERM);
> return -EPERM;
> }
>
> @@ -992,7 +992,8 @@ static int evm_inode_setattr(struct mnt_idmap *idmap,
> struct dentry *dentry,
>
> integrity_audit_msg(AUDIT_INTEGRITY_METADATA, d_backing_inode(dentry),
> dentry->d_name.name, "appraise_metadata",
> - integrity_status_msg[evm_status], -EPERM, 0);
> + integrity_status_msg[evm_status], -EPERM, 0,
> + -EPERM);
> return -EPERM;
> }
>
> diff --git a/security/integrity/ima/ima_api.c
> b/security/integrity/ima/ima_api.c
> index
> 122d127e108dcca8ddae6575c908144859783fb6..f765bfe5db68d0847cfe5b47f81b64018083
> f65a 100644
> --- a/security/integrity/ima/ima_api.c
> +++ b/security/integrity/ima/ima_api.c
> @@ -116,7 +116,7 @@ int ima_store_template(struct ima_template_entry *entry,
> if (result < 0) {
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode,
> template_name, op,
> - audit_cause, result, 0);
> + audit_cause, result, 0, result);
> return result;
> }
> }
> @@ -159,7 +159,7 @@ void ima_add_violation(struct file *file, const unsigned
> char *filename,
> ima_free_template_entry(entry);
> err_out:
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
> - op, cause, result, 0);
> + op, cause, result, 0, result);
> }
>
> /**
> @@ -330,7 +330,7 @@ int ima_collect_measurement(struct ima_iint_cache *iint,
> struct file *file,
>
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode,
> filename.name.name, "collect_data",
> - audit_cause, result, 0);
> + audit_cause, result, 0, result);
>
> release_dentry_name_snapshot(&filename);
> }
> @@ -383,7 +383,7 @@ void ima_store_measurement(struct ima_iint_cache *iint,
> struct file *file,
> result = ima_alloc_init_template(&event_data, &entry, template_desc);
> if (result < 0) {
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
> - op, audit_cause, result, 0);
> + op, audit_cause, result, 0, result);
> return;
> }
>
> diff --git a/security/integrity/ima/ima_appraise.c
> b/security/integrity/ima/ima_appraise.c
> index
> b280488e15fcb0b6f8a8a0caaab93c7d511e4a40..6dc712f430f44ee18c3418a6bf4cd4da4975
> 8b98 100644
> --- a/security/integrity/ima/ima_appraise.c
> +++ b/security/integrity/ima/ima_appraise.c
> @@ -564,7 +564,7 @@ int ima_appraise_measurement(enum ima_hooks func, struct
> ima_iint_cache *iint,
> status = INTEGRITY_FAIL;
> cause = "unverifiable-signature";
> integrity_audit_msg(audit_msgno, inode, filename,
> - op, cause, rc, 0);
> + op, cause, rc, 0, rc);
> } else if (status != INTEGRITY_PASS) {
> /* Fix mode, but don't replace file signatures. */
> if ((ima_appraise & IMA_APPRAISE_FIX) && !try_modsig &&
> @@ -589,7 +589,7 @@ int ima_appraise_measurement(enum ima_hooks func, struct
> ima_iint_cache *iint,
> }
>
> integrity_audit_msg(audit_msgno, inode, filename,
> - op, cause, rc, 0);
> + op, cause, rc, 0, rc);
> } else {
> ima_cache_flags(iint, func);
> }
> @@ -752,7 +752,7 @@ static int validate_hash_algo(struct dentry *dentry,
> path = NULL;
>
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, d_inode(dentry), path,
> - "set_data", errmsg, -EACCES, 0);
> + "set_data", errmsg, -EACCES, 0, -EACCES);
>
> kfree(pathbuf);
>
> diff --git a/security/integrity/ima/ima_fs.c b/security/integrity/ima/ima_fs.c
> index
> 2a0bca5543161912abe2a0236c9fcae7055e62bc..6d2ef44b21f8d40b4981a6a441cf7c3d69f9
> 4dee 100644
> --- a/security/integrity/ima/ima_fs.c
> +++ b/security/integrity/ima/ima_fs.c
> @@ -595,7 +595,7 @@ static ssize_t ima_write_policy(struct file *file, const
> char __user *buf,
> pr_err("signed policy file (specified as an absolute pathname) required\n");
> integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> "policy_update", "signed policy required",
> - 1, 0);
> + 1, 0, -EINVAL);
Here it could be put -EACCES as errno, being the value returned for this case.
> result = -EACCES;
> } else {
> ima_measure_raw_policy(data, datalen);
> @@ -745,7 +745,7 @@ static int ima_release_policy(struct inode *inode, struct
> file *file)
>
> pr_info("policy update %s\n", cause);
> integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> - "policy_update", cause, !valid_policy, 0);
> + "policy_update", cause, !valid_policy, 0, 0);
Here maybe it could be put a conditional errno, based on the validity of the
policy, instead of hardcoding a zero.
Regards,
Enrico
> if (!valid_policy) {
> ima_delete_rules();
> diff --git a/security/integrity/ima/ima_init.c
> b/security/integrity/ima/ima_init.c
> index
> d53f4d89a53e56d7ebb31950c10b37fc89782753..7a76e2686267482b10bf854a76829c60ef9f
> 1e1b 100644
> --- a/security/integrity/ima/ima_init.c
> +++ b/security/integrity/ima/ima_init.c
> @@ -103,7 +103,7 @@ static int __init ima_add_boot_aggregate(void)
> return 0;
> err_out:
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, filename, op,
> - audit_cause, result, 0);
> + audit_cause, result, 0, result);
> return result;
> }
>
> diff --git a/security/integrity/ima/ima_main.c
> b/security/integrity/ima/ima_main.c
> index
> ab1e53b3210d3a4d3f91d65f7db19e6a2a2d401c..9e80f40680d7be08d14d26ba48ed334d4e4a
> b10c 100644
> --- a/security/integrity/ima/ima_main.c
> +++ b/security/integrity/ima/ima_main.c
> @@ -119,7 +119,7 @@ static int mmap_violation_check(enum ima_hooks func,
> struct file *file,
> *pathname = ima_d_path(&file->f_path, pathbuf,
> filename);
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode, *pathname,
> - "mmap_file", "mmapped_writers", rc, 0);
> + "mmap_file", "mmapped_writers", rc, 0, rc);
> }
> return rc;
> }
> @@ -466,7 +466,7 @@ static int process_measurement(struct file *file, const
> struct cred *cred,
>
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, file_inode(file),
> pathname, "collect_data",
> - "denied-hash-algorithm", rc, 0);
> + "denied-hash-algorithm", rc, 0, rc);
> }
> out_locked:
> if ((mask & MAY_WRITE) && test_bit(IMA_DIGSIG, &iint->atomic_flags) &&
> @@ -579,7 +579,8 @@ static int ima_file_mprotect(struct vm_area_struct *vma,
> unsigned long reqprot,
> file = vma->vm_file;
> pathname = ima_d_path(&file->f_path, &pathbuf, filename);
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode, pathname,
> - "collect_data", "failed-mprotect", result, 0);
> + "collect_data", "failed-mprotect", result, 0,
> + result);
> if (pathbuf)
> __putname(pathbuf);
>
> diff --git a/security/integrity/ima/ima_policy.c
> b/security/integrity/ima/ima_policy.c
> index
> 68d9a5e6c232ea0678e9f51f105cebecccccb43e..9013c962dc0bfd6184948230ad6746e71f6e
> 82f5 100644
> --- a/security/integrity/ima/ima_policy.c
> +++ b/security/integrity/ima/ima_policy.c
> @@ -1992,7 +1992,8 @@ ssize_t ima_parse_add_rule(char *rule)
> entry = kzalloc_obj(*entry);
> if (!entry) {
> integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL,
> - NULL, op, "-ENOMEM", -ENOMEM, audit_info);
> + NULL, op, "-ENOMEM", -ENOMEM, audit_info,
> + -ENOMEM);
> return -ENOMEM;
> }
>
> @@ -2003,7 +2004,7 @@ ssize_t ima_parse_add_rule(char *rule)
> ima_free_rule(entry);
> integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL,
> NULL, op, "invalid-policy", result,
> - audit_info);
> + audit_info, result);
> return result;
> }
>
> @@ -2421,7 +2422,7 @@ void ima_measure_loaded_policy(void)
> rule = kmalloc(rule_len, GFP_KERNEL);
> if (!rule) {
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, event_name,
> - op, "ENOMEM", result, 0);
> + op, "ENOMEM", result, 0, result);
> return;
> }
>
> @@ -2440,7 +2441,7 @@ void ima_measure_loaded_policy(void)
> result = -E2BIG;
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL,
> event_name, op, "rule_length",
> - result, 0);
> + result, 0, result);
> rcu_read_unlock();
> goto free_rule;
> }
> @@ -2454,7 +2455,7 @@ void ima_measure_loaded_policy(void)
> file.buf = kmalloc(file_len, GFP_KERNEL);
> if (!file.buf) {
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, NULL, event_name,
> - op, "ENOMEM", result, 0);
> + op, "ENOMEM", result, 0, result);
> goto free_rule;
> }
>
> diff --git a/security/integrity/ima/ima_queue.c
> b/security/integrity/ima/ima_queue.c
> index
> f89f0ca3d4edf16a7147b3c23d25fc2cf18044c6..8d3282ff7da4131ae4389bf832442285e500
> 542d 100644
> --- a/security/integrity/ima/ima_queue.c
> +++ b/security/integrity/ima/ima_queue.c
> @@ -292,7 +292,7 @@ int ima_add_template_entry(struct ima_template_entry
> *entry, int violation,
> out:
> mutex_unlock(&ima_extend_list_mutex);
> integrity_audit_msg(AUDIT_INTEGRITY_PCR, inode, filename,
> - op, audit_cause, result, audit_info);
> + op, audit_cause, result, audit_info, result);
> return result;
> }
>
> diff --git a/security/integrity/ima/ima_template_lib.c
> b/security/integrity/ima/ima_template_lib.c
> index
> 8a89236f926c10af0dd2b2ef08fbe59bd8a78b66..9bd80ca1159a2fe24b3ea3308a118f6beea7
> 33cb 100644
> --- a/security/integrity/ima/ima_template_lib.c
> +++ b/security/integrity/ima/ima_template_lib.c
> @@ -392,7 +392,7 @@ int ima_eventdigest_init(struct ima_event_data
> *event_data,
> if (result) {
> integrity_audit_msg(AUDIT_INTEGRITY_DATA, inode,
> event_data->filename, "collect_data",
> - "failed", result, 0);
> + "failed", result, 0, result);
> return result;
> }
> cur_digest = hash_hdr->digest;
> diff --git a/security/integrity/integrity.h b/security/integrity/integrity.h
> index
> 0c581c03c5da72d80e9c352a7adff1fb89628644..2ab6b7e34e7ee2dd29ae03ae1fb45fa26d9c
> 032a 100644
> --- a/security/integrity/integrity.h
> +++ b/security/integrity/integrity.h
> @@ -218,7 +218,8 @@ static inline void evm_load_x509(void)
> /* declarations */
> void integrity_audit_msg(int audit_msgno, struct inode *inode,
> const unsigned char *fname, const char *op,
> - const char *cause, int result, int info);
> + const char *cause, int result, int info,
> + int errno);
>
> void integrity_audit_message(int audit_msgno, struct inode *inode,
> const unsigned char *fname, const char *op,
> @@ -235,7 +236,7 @@ integrity_audit_log_start(struct audit_context *ctx, gfp_t
> gfp_mask, int type)
> static inline void integrity_audit_msg(int audit_msgno, struct inode *inode,
> const unsigned char *fname,
> const char *op, const char *cause,
> - int result, int info)
> + int result, int info, int errno)
> {
> }
>
> diff --git a/security/integrity/integrity_audit.c
> b/security/integrity/integrity_audit.c
> index
> d8d9e5ff1cd22b091f462d1e83d28d2d6bd983e9..2dd2d7e3916e7bf35c753450315ff22e2d02
> 92b7 100644
> --- a/security/integrity/integrity_audit.c
> +++ b/security/integrity/integrity_audit.c
> @@ -27,10 +27,11 @@ __setup("integrity_audit=", integrity_audit_setup);
>
> void integrity_audit_msg(int audit_msgno, struct inode *inode,
> const unsigned char *fname, const char *op,
> - const char *cause, int result, int audit_info)
> + const char *cause, int result, int audit_info,
> + int errno)
> {
> integrity_audit_message(audit_msgno, inode, fname, op, cause,
> - result, audit_info, 0);
> + result, audit_info, errno);
> }
>
> void integrity_audit_message(int audit_msgno, struct inode *inode,
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
2026-09-17 22:58 ` Enrico Bravi
@ 2026-09-18 21:11 ` Frederick Lawler
2026-09-20 13:16 ` Enrico Bravi
0 siblings, 1 reply; 7+ messages in thread
From: Frederick Lawler @ 2026-09-18 21:11 UTC (permalink / raw)
To: Enrico Bravi
Cc: zohar@linux.ibm.com, roberto.sassu@huawei.com,
eric.snowberg@oracle.com, paul@paul-moore.com,
dmitry.kasatkin@gmail.com, serge@hallyn.com, jmorris@namei.org,
linux-security-module@vger.kernel.org,
linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org,
kernel-team@cloudflare.com
Hi Enrico,
On Thu, Sep 17, 2026 at 10:58:22PM +0000, Enrico Bravi wrote:
> Hi Frederick,
>
> On Wed, 2026-09-16 at 16:36 -0500, Frederick Lawler wrote:
> > integrity_audit_msg() hides error codes by wrapping
> > integrity_audit_message() which obfuscates the underlying reason for the
> > failure.
> >
> > Update integrity_audit_msg() call sites
>
> here it could be mentioned that also integrity_audit_msg() itself is
> updated.
Good point. I can see that I may have not been clear about that.
> > diff --git a/security/integrity/ima/ima_fs.c b/security/integrity/ima/ima_fs.c
> > index
> > 2a0bca5543161912abe2a0236c9fcae7055e62bc..6d2ef44b21f8d40b4981a6a441cf7c3d69f9
> > 4dee 100644
> > --- a/security/integrity/ima/ima_fs.c
> > +++ b/security/integrity/ima/ima_fs.c
> > @@ -595,7 +595,7 @@ static ssize_t ima_write_policy(struct file *file, const
> > char __user *buf,
> > pr_err("signed policy file (specified as an absolute pathname) required\n");
> > integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> > "policy_update", "signed policy required",
> > - 1, 0);
> > + 1, 0, -EINVAL);
>
> Here it could be put -EACCES as errno, being the value returned for this case.
Sashiko said the same. I kept going back and forth on this one because
of what the message actually says. EACCES is the result, but the string
itself + pr_error() implies that it's an input error. Similar to
ima_release_policy() below, I should probably keep this zero, and
follow up.
> > result = -EACCES;
> > } else {
> > ima_measure_raw_policy(data, datalen);
> > @@ -745,7 +745,7 @@ static int ima_release_policy(struct inode *inode, struct
> > file *file)
> >
> > pr_info("policy update %s\n", cause);
> > integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> > - "policy_update", cause, !valid_policy, 0);
> > + "policy_update", cause, !valid_policy, 0, 0);
>
> Here maybe it could be put a conditional errno, based on the validity of the
> policy, instead of hardcoding a zero.
I can see that making sense to throw a -EINVAL on it. The function
is designed to always succeed, but it might be worth pulling out the
error code from ima_check_policy() for this case.
Best,
Fred
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
2026-09-16 21:36 ` [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg() Frederick Lawler
@ 2026-09-18 21:49 ` Mimi Zohar
0 siblings, 0 replies; 7+ messages in thread
From: Mimi Zohar @ 2026-09-18 21:49 UTC (permalink / raw)
To: Frederick Lawler, Roberto Sassu, Dmitry Kasatkin, Eric Snowberg,
Paul Moore, James Morris, Serge E. Hallyn
Cc: linux-integrity, linux-security-module, linux-kernel, kernel-team
Hi Fred,
On Wed, 2026-09-16 at 16:36 -0500, Frederick Lawler wrote:
> integrity_audit_msg() wraps integrity_audit_message(). Replace remaining
> call sites with the truncated function name. Then remove it since there
> are no more callers.
>
> Signed-off-by: Frederick Lawler <fred@cloudflare.com>
I agree with Enrico on the 1/2 patch description. This patch description
similarly should say something like:
Now that integrity_audit_msg() accepts an errno parameter, it is equivalent to
integrity_audit_message(). Convert the couple of integrity_audit_message()
callers to integrity_audit_msg() and remove integrity_audit_message().
Mimi
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
2026-09-18 21:11 ` Frederick Lawler
@ 2026-09-20 13:16 ` Enrico Bravi
0 siblings, 0 replies; 7+ messages in thread
From: Enrico Bravi @ 2026-09-20 13:16 UTC (permalink / raw)
To: Frederick Lawler
Cc: zohar@linux.ibm.com, roberto.sassu@huawei.com,
eric.snowberg@oracle.com, paul@paul-moore.com,
dmitry.kasatkin@gmail.com, serge@hallyn.com, jmorris@namei.org,
linux-security-module@vger.kernel.org,
linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org,
kernel-team@cloudflare.com
On Fri, 2026-09-18 at 16:11 -0500, Frederick Lawler wrote:
> Hi Enrico,
>
> On Thu, Sep 17, 2026 at 10:58:22PM +0000, Enrico Bravi wrote:
> > Hi Frederick,
> >
> > On Wed, 2026-09-16 at 16:36 -0500, Frederick Lawler wrote:
> > > integrity_audit_msg() hides error codes by wrapping
> > > integrity_audit_message() which obfuscates the underlying reason for the
> > > failure.
> > >
> > > Update integrity_audit_msg() call sites
> >
> > here it could be mentioned that also integrity_audit_msg() itself is
> > updated.
>
> Good point. I can see that I may have not been clear about that.
>
> > > diff --git a/security/integrity/ima/ima_fs.c
> > > b/security/integrity/ima/ima_fs.c
> > > index
> > > 2a0bca5543161912abe2a0236c9fcae7055e62bc..6d2ef44b21f8d40b4981a6a441cf7c3d
> > > 69f9
> > > 4dee 100644
> > > --- a/security/integrity/ima/ima_fs.c
> > > +++ b/security/integrity/ima/ima_fs.c
> > > @@ -595,7 +595,7 @@ static ssize_t ima_write_policy(struct file *file,
> > > const
> > > char __user *buf,
> > > pr_err("signed policy file (specified as an absolute pathname)
> > > required\n");
> > > integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> > > "policy_update", "signed policy required",
> > > - 1, 0);
> > > + 1, 0, -EINVAL);
> >
> > Here it could be put -EACCES as errno, being the value returned for this
> > case.
>
> Sashiko said the same. I kept going back and forth on this one because
> of what the message actually says. EACCES is the result, but the string
> itself + pr_error() implies that it's an input error. Similar to
> ima_release_policy() below, I should probably keep this zero, and
> follow up.
Hi Frederick,
AFAIU these messages justify why the policy loading has been denied. The point
seems to be that the input policy, even if it is valid, cannot be verified in
that form, because the signature is missing. The user can write the policy
directly on the securityfs file, but is not allowed to when a signed policy
is required. For this reason,
-EACCES could be better, because it is referring to an action permitted by the
system, but not allowed by the current policy.
Regards,
Enrico
> > > result = -EACCES;
> > > } else {
> > > ima_measure_raw_policy(data, datalen);
> > > @@ -745,7 +745,7 @@ static int ima_release_policy(struct inode *inode,
> > > struct
> > > file *file)
> > >
> > > pr_info("policy update %s\n", cause);
> > > integrity_audit_msg(AUDIT_INTEGRITY_STATUS, NULL, NULL,
> > > - "policy_update", cause, !valid_policy, 0);
> > > + "policy_update", cause, !valid_policy, 0, 0);
> >
> > Here maybe it could be put a conditional errno, based on the validity of the
> > policy, instead of hardcoding a zero.
>
> I can see that making sense to throw a -EINVAL on it. The function
> is designed to always succeed, but it might be worth pulling out the
> error code from ima_check_policy() for this case.
>
> Best,
> Fred
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-09-20 13:16 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 21:36 [PATCH v3 0/2] integrity: Return error codes in audit messages Frederick Lawler
2026-09-16 21:36 ` [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites Frederick Lawler
2026-09-17 22:58 ` Enrico Bravi
2026-09-18 21:11 ` Frederick Lawler
2026-09-20 13:16 ` Enrico Bravi
2026-09-16 21:36 ` [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg() Frederick Lawler
2026-09-18 21:49 ` Mimi Zohar
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).