diff options
author | Mimi Zohar <zohar@linux.ibm.com> | 2021-06-02 16:33:39 -0400 |
---|---|---|
committer | Mimi Zohar <zohar@linux.ibm.com> | 2021-06-10 16:36:41 -0400 |
commit | 55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a (patch) | |
tree | f01d9e8426aba01c4263307e43538fbdd52f4139 | |
parent | 7d2201d46218df951004fc48897f89c6eb510b69 (diff) | |
download | linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.tar.gz linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.tar.bz2 linux-55748ac6a6d3e35f8fd0f5c9284df7c7f3b1705a.zip |
ima: differentiate between EVM failures in the audit log
Differentiate between an invalid EVM portable signature failure
from other EVM HMAC/signature failures.
Reviewed-by: Roberto Sassu <roberto.sassu@huawei.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
-rw-r--r-- | security/integrity/ima/ima_appraise.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/security/integrity/ima/ima_appraise.c b/security/integrity/ima/ima_appraise.c index 940695e7b535..ef9dcfce45d4 100644 --- a/security/integrity/ima/ima_appraise.c +++ b/security/integrity/ima/ima_appraise.c @@ -422,7 +422,8 @@ int ima_appraise_measurement(enum ima_hooks func, goto out; case INTEGRITY_FAIL_IMMUTABLE: set_bit(IMA_DIGSIG, &iint->atomic_flags); - fallthrough; + cause = "invalid-fail-immutable"; + goto out; case INTEGRITY_FAIL: /* Invalid HMAC/signature. */ cause = "invalid-HMAC"; goto out; |