[PATCH v4 1/2] integrity: Report error code in integrity_audit_msg() call sites

sashiko-bot at kernel.org sashiko-bot at kernel.org
Thu Sep 24 20:40:16 UTC 2026


> integrity_audit_msg() hides error codes by wrapping
> integrity_audit_message() which obfuscates the underlying reason for the
> failure.
> 
> Update integrity_audit_msg() to take a errno argument, and pass that
> through to integrity_audit_message(). Then update call sites to
> take caller's respective error codes.
> 
> ima_appraise_measurement() stores xattr_len as the return code, but
> can replace it with a error code later. Therefore conditionally use
> a code if rc < 0, otherwise report zero. Lastly, conditionally use
> -EINVAL for ima_release_policy().
> 
> Signed-off-by: Frederick Lawler <fred at cloudflare.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-report-hash-error-v4-0-196ca6350619@cloudflare.com?part=1




More information about the Linux-security-module-archive mailing list