From 70a807a42f2c03693344a9ea7a3eceb427502501 Mon Sep 17 00:00:00 2001 From: Ben Hutchings Date: Sun, 5 May 2019 13:45:06 +0100 Subject: [PATCH] MODSIGN: Make shash allocation failure fatal mod_is_hash_blacklisted() currently returns 0 (suceess) if crypto_alloc_shash() fails. This should instead be a fatal error, so unwrap and pass up the error code. Signed-off-by: Ben Hutchings Gbp-Pq: Topic features/all/db-mok-keyring Gbp-Pq: Name modsign-make-shash-allocation-failure-fatal.patch --- kernel/module_signing.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/kernel/module_signing.c b/kernel/module_signing.c index ee3a87fb2e7..3afff3718d7 100644 --- a/kernel/module_signing.c +++ b/kernel/module_signing.c @@ -47,11 +47,13 @@ static int mod_is_hash_blacklisted(const void *mod, size_t verifylen) struct shash_desc *desc; size_t digest_size, desc_size; u8 *digest; - int ret = 0; + int ret; tfm = crypto_alloc_shash("sha256", 0, 0); - if (IS_ERR(tfm)) + if (IS_ERR(tfm)) { + ret = PTR_ERR(tfm); goto error_return; + } desc_size = crypto_shash_descsize(tfm) + sizeof(*desc); digest_size = crypto_shash_digestsize(tfm); -- 2.30.2