diff options
author | Mimi Zohar <zohar@linux.ibm.com> | 2021-06-02 22:33:39 +0200 |
---|---|---|
committer | Mimi Zohar <zohar@linux.ibm.com> | 2021-06-10 22:36:41 +0200 |
commit | 55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a (patch) | |
tree | f01d9e8426aba01c4263307e43538fbdd52f4139 /security/integrity/ima/ima_appraise.c | |
parent | ima: Fix fall-through warning for Clang (diff) | |
download | linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.tar.xz linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.zip |
ima: differentiate between EVM failures in the audit log
Differentiate between an invalid EVM portable signature failure
from other EVM HMAC/signature failures.
Reviewed-by: Roberto Sassu <roberto.sassu@huawei.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Diffstat (limited to 'security/integrity/ima/ima_appraise.c')
-rw-r--r-- | security/integrity/ima/ima_appraise.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c index 940695e7b535..ef9dcfce45d4 100644 --- a/security/integrity/ima/ima_appraise.c +++ b/security/integrity/ima/ima_appraise.c @@ -422,7 +422,8 @@ int ima_appraise_measurement(enum ima_hooks func, goto out; case INTEGRITY_FAIL_IMMUTABLE: set_bit(IMA_DIGSIG, &iint->atomic_flags); - fallthrough; + cause = "invalid-fail-immutable"; + goto out; case INTEGRITY_FAIL: /* Invalid HMAC/signature. */ cause = "invalid-HMAC"; goto out; |