Load tomoyo linux manually
tomoyo-loadpolicy [option]
tomoyo-loadpolicy [option] [remote_ip:remote_port]
This program reads \s-1TOMOYO\s0 Linux policy from standard input and loads it into the kernel.
Append to /sys/kernel/security/tomoyo/exception_policy.
Overwrite /sys/kernel/security/tomoyo/exception_policy.
Append to /sys/kernel/security/tomoyo/domain_policy.
Overwrite /sys/kernel/security/tomoyo/domain_policy.
Append to /sys/kernel/security/tomoyo/manager.
Append to /sys/kernel/security/tomoyo/profile.
Append to /sys/kernel/security/tomoyo/stat.
Write to policy on a remote system via an agent waiting at port remote_port on \s-1IP\s0 address remote_ip.
echo "acl_group 0 file read proc:/meminfo" | tomoyo-loadpolicy -e
echo "delete acl_group 0 file read proc:/meminfo" | tomoyo-loadpolicy -e
( echo "<kernel>"; echo "file execute /sbin/init" ) | tomoyo-loadpolicy -d
tomoyo-loadpolicy -df < /etc/tomoyo/domain_policy.conf
tomoyo-loadpolicy -d 192.168.1.1:10000 < /etc/tomoyo/192.168.1.1/domain_policy.conf echo "delete /usr/sbin/tomoyo-queryd" | tomoyo-loadpolicy -m
If you find any bugs, send an email to <[email protected]>.
Main author.
Documentation and website.
tomoyo-savepolicy(8), tomoyo-editpolicy(8), tomoyo-editpolicy-agent(8), tomoyo-init(8)
See <http://tomoyo.sourceforge.jp> for more information.