evm: audit integrity metadata failures
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Thu, 21 Feb 2013 14:31:22 +0000 (09:31 -0500)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Thu, 20 Jun 2013 11:47:50 +0000 (07:47 -0400)
commit9b97b6cdd420cd62dae972eafaae7494a7670607
tree4f5958063eb57849e4687e4c5366b1212a1d9d6a
parentd726d8d719b6ac919cc4d5cae73831a2ffe36118
evm: audit integrity metadata failures

Before modifying an EVM protected extended attribute or any other
metadata included in the HMAC calculation, the existing 'security.evm'
is verified.  This patch adds calls to integrity_audit_msg() to audit
integrity metadata failures.

Reported-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
security/integrity/evm/evm_main.c
This page took 0.025866 seconds and 5 git commands to generate.