Re: [PATCH v3] ipe: fix invalid sgid value in audit event documentation
From: Randy Dunlap
Date: Wed Sep 02 2026 - 14:36:50 EST
On 9/2/26 8:29 AM, Manuel Ebner wrote:
> From: Manuel Ebner <manuelebner@xxxxxxxxxxx>
>
> The audit event example in the IPE documentation contains 'sgid=)',
> which is not a valid Set Group ID value. Fix it to use 'sgid=0'.
>
> Fixes: ac6731870ed9 ("documentation: add IPE documentation")
> Signed-off-by: Manuel Ebner <manuelebner@xxxxxxxxxxx>
Reviewed-by: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
Thanks.
> ---
> [v3]
> Really fix commit message.
>
> [v2]
> Add Fixes tag.
> Fix commit message
>
> Thanks for the help Fan Wu.
> ---
> Documentation/admin-guide/LSM/ipe.rst | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/Documentation/admin-guide/LSM/ipe.rst b/Documentation/admin-guide/LSM/ipe.rst
> index a756d8158531..bebf14fc2411 100644
> --- a/Documentation/admin-guide/LSM/ipe.rst
> +++ b/Documentation/admin-guide/LSM/ipe.rst
> @@ -502,11 +502,11 @@ The following table lists the error codes that may appear in the errno field whi
> Event Examples::
>
> type=1404 audit(1653425689.008:55): enforcing=0 old_enforcing=1 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1
> - type=1300 audit(1653425689.008:55): arch=c000003e syscall=1 success=yes exit=2 a0=1 a1=55c1065e5c60 a2=2 a3=0 items=0 ppid=405 pid=441 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=)
> + type=1300 audit(1653425689.008:55): arch=c000003e syscall=1 success=yes exit=2 a0=1 a1=55c1065e5c60 a2=2 a3=0 items=0 ppid=405 pid=441 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
> type=1327 audit(1653425689.008:55): proctitle="-bash"
>
> type=1404 audit(1653425689.008:55): enforcing=1 old_enforcing=0 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1
> - type=1300 audit(1653425689.008:55): arch=c000003e syscall=1 success=yes exit=2 a0=1 a1=55c1065e5c60 a2=2 a3=0 items=0 ppid=405 pid=441 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=)
> + type=1300 audit(1653425689.008:55): arch=c000003e syscall=1 success=yes exit=2 a0=1 a1=55c1065e5c60 a2=2 a3=0 items=0 ppid=405 pid=441 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
> type=1327 audit(1653425689.008:55): proctitle="-bash"
>
> This record will always be emitted in conjunction with a ``AUDITSYSCALL`` record for the ``write`` syscall.
--
~Randy