evm: audit integrity metadata failures
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Thu, 21 Feb 2013 14:31:22 +0000 (09:31 -0500)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Thu, 20 Jun 2013 11:47:50 +0000 (07:47 -0400)
Before modifying an EVM protected extended attribute or any other
metadata included in the HMAC calculation, the existing 'security.evm'
is verified.  This patch adds calls to integrity_audit_msg() to audit
integrity metadata failures.

Reported-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>

No differences found