[PATCH 5/6] ipe: fix enforcement audit
Fan Wu
wufan at kernel.org
Sat Oct 3 02:51:34 UTC 2026
ipe_audit_enforce() starts an audit buffer but writes the state change
with audit_log(), which logs its own record. Ending the unused buffer
then emits an extra empty AUDIT_MAC_STATUS record.
Remove the unused buffer and log the state change with audit_log()
alone.
Fixes: a68916eaedcd ("ipe: add permissive toggle")
Assisted-by: LLM
Signed-off-by: Fan Wu <wufan at kernel.org>
---
security/ipe/audit.c | 8 --------
1 file changed, 8 deletions(-)
diff --git a/security/ipe/audit.c b/security/ipe/audit.c
index 5b4f24914c74..b6f8fb54085a 100644
--- a/security/ipe/audit.c
+++ b/security/ipe/audit.c
@@ -262,18 +262,10 @@ void ipe_audit_policy_load(const struct ipe_policy *const p)
*/
void ipe_audit_enforce(bool new_enforce, bool old_enforce)
{
- struct audit_buffer *ab;
-
- ab = audit_log_start(audit_context(), GFP_KERNEL, AUDIT_MAC_STATUS);
- if (!ab)
- return;
-
audit_log(audit_context(), GFP_KERNEL, AUDIT_MAC_STATUS,
"enforcing=%d old_enforcing=%d auid=%u ses=%u"
" enabled=1 old-enabled=1 lsm=ipe res=1",
new_enforce, old_enforce,
from_kuid(&init_user_ns, audit_get_loginuid(current)),
audit_get_sessionid(current));
-
- audit_log_end(ab);
}
--
2.55.0
More information about the Linux-security-module-archive
mailing list