summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMimi Zohar <zohar@linux.ibm.com>2021-06-02 16:33:39 -0400
committerMimi Zohar <zohar@linux.ibm.com>2021-06-10 16:36:41 -0400
commit55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a (patch)
treef01d9e8426aba01c4263307e43538fbdd52f4139
parent7d2201d46218df951004fc48897f89c6eb510b69 (diff)
downloadlinux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.tar.gz
linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.tar.bz2
linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.zip
ima: differentiate between EVM failures in the audit log
Differentiate between an invalid EVM portable signature failure from other EVM HMAC/signature failures. Reviewed-by: Roberto Sassu <roberto.sassu@huawei.com> Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
-rw-r--r--security/integrity/ima/ima_appraise.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c
index 940695e7b535..ef9dcfce45d4 100644
--- a/security/integrity/ima/ima_appraise.c
+++ b/security/integrity/ima/ima_appraise.c
@@ -422,7 +422,8 @@ int ima_appraise_measurement(enum ima_hooks func,
goto out;
case INTEGRITY_FAIL_IMMUTABLE:
set_bit(IMA_DIGSIG, &iint->atomic_flags);
- fallthrough;
+ cause = "invalid-fail-immutable";
+ goto out;
case INTEGRITY_FAIL: /* Invalid HMAC/signature. */
cause = "invalid-HMAC";
goto out;