[PATCH v4 1/2] integrity: Report error code in integrity_audit_msg() call sites
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Thu Sep 24 20:40:16 UTC 2026
> integrity_audit_msg() hides error codes by wrapping
> integrity_audit_message() which obfuscates the underlying reason for the
> failure.
>
> Update integrity_audit_msg() to take a errno argument, and pass that
> through to integrity_audit_message(). Then update call sites to
> take caller's respective error codes.
>
> ima_appraise_measurement() stores xattr_len as the return code, but
> can replace it with a error code later. Therefore conditionally use
> a code if rc < 0, otherwise report zero. Lastly, conditionally use
> -EINVAL for ima_release_policy().
>
> Signed-off-by: Frederick Lawler <fred at cloudflare.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-report-hash-error-v4-0-196ca6350619@cloudflare.com?part=1
More information about the Linux-security-module-archive
mailing list