/*
  * authentication
  */
-static int get_authorizer(struct ceph_connection *con,
-                         void **buf, int *len, int *proto,
-                         void **reply_buf, int *reply_len, int force_new)
+
+/*
+ * Note: returned pointer is the address of a structure that's
+ * managed separately.  Caller must *not* attempt to free it.
+ */
+static struct ceph_auth_handshake *get_authorizer(struct ceph_connection *con,
+                                       void **buf, int *len, int *proto,
+                                       void **reply_buf, int *reply_len,
+                                       int force_new)
 {
        struct ceph_mds_session *s = con->private;
        struct ceph_mds_client *mdsc = s->s_mdsc;
        struct ceph_auth_client *ac = mdsc->fsc->client->monc.auth;
        struct ceph_auth_handshake *auth = &s->s_auth;
-       int ret = 0;
 
        if (force_new && auth->authorizer) {
                if (ac->ops && ac->ops->destroy_authorizer)
                auth->authorizer = NULL;
        }
        if (!auth->authorizer && ac->ops && ac->ops->create_authorizer) {
-               ret = ac->ops->create_authorizer(ac, CEPH_ENTITY_TYPE_MDS, auth);
+               int ret = ac->ops->create_authorizer(ac, CEPH_ENTITY_TYPE_MDS,
+                                                       auth);
                if (ret)
-                       return ret;
+                       return ERR_PTR(ret);
        }
 
        *proto = ac->protocol;
        *reply_buf = auth->authorizer_reply_buf;
        *reply_len = auth->authorizer_reply_buf_len;
 
-       return 0;
+       return auth;
 }
 
 
 
        void (*dispatch) (struct ceph_connection *con, struct ceph_msg *m);
 
        /* authorize an outgoing connection */
-       int (*get_authorizer) (struct ceph_connection *con,
-                              void **buf, int *len, int *proto,
-                              void **reply_buf, int *reply_len, int force_new);
+       struct ceph_auth_handshake *(*get_authorizer) (
+                               struct ceph_connection *con,
+                               void **buf, int *len, int *proto,
+                               void **reply_buf, int *reply_len,
+                               int force_new);
        int (*verify_authorizer_reply) (struct ceph_connection *con, int len);
        int (*invalidate_authorizer)(struct ceph_connection *con);
 
 
        void *auth_buf;
        int auth_len;
        int auth_protocol;
-       int ret;
+       struct ceph_auth_handshake *auth;
 
        if (!con->ops->get_authorizer) {
                con->out_connect.authorizer_protocol = CEPH_AUTH_UNKNOWN;
        auth_buf = NULL;
        auth_len = 0;
        auth_protocol = CEPH_AUTH_UNKNOWN;
-       ret = con->ops->get_authorizer(con, &auth_buf, &auth_len,
+       auth = con->ops->get_authorizer(con, &auth_buf, &auth_len,
                                &auth_protocol, &con->auth_reply_buf,
                                &con->auth_reply_buf_len, con->auth_retry);
        mutex_lock(&con->mutex);
 
-       if (ret)
-               return ret;
+       if (IS_ERR(auth))
+               return PTR_ERR(auth);
 
        if (test_bit(CLOSED, &con->state) || test_bit(OPENING, &con->state))
                return -EAGAIN;
 
 /*
  * authentication
  */
-static int get_authorizer(struct ceph_connection *con,
-                         void **buf, int *len, int *proto,
-                         void **reply_buf, int *reply_len, int force_new)
+/*
+ * Note: returned pointer is the address of a structure that's
+ * managed separately.  Caller must *not* attempt to free it.
+ */
+static struct ceph_auth_handshake *get_authorizer(struct ceph_connection *con,
+                                       void **buf, int *len, int *proto,
+                                       void **reply_buf, int *reply_len,
+                                       int force_new)
 {
        struct ceph_osd *o = con->private;
        struct ceph_osd_client *osdc = o->o_osdc;
        struct ceph_auth_client *ac = osdc->client->monc.auth;
        struct ceph_auth_handshake *auth = &o->o_auth;
-       int ret = 0;
 
        if (force_new && auth->authorizer) {
                if (ac->ops && ac->ops->destroy_authorizer)
                auth->authorizer = NULL;
        }
        if (!auth->authorizer && ac->ops && ac->ops->create_authorizer) {
-               ret = ac->ops->create_authorizer(ac, CEPH_ENTITY_TYPE_OSD, auth);
+               int ret = ac->ops->create_authorizer(ac, CEPH_ENTITY_TYPE_OSD,
+                                                       auth);
                if (ret)
-                       return ret;
+                       return ERR_PTR(ret);
        }
 
        *proto = ac->protocol;
        *reply_buf = auth->authorizer_reply_buf;
        *reply_len = auth->authorizer_reply_buf_len;
 
-       return 0;
+       return auth;
 }