Policy violation notification daemon for tomoyo linux
tomoyo-notifyd
This program notifies the system administrator of policy violations that occur in domains set to enforcing mode.
The notification method can be any arbitrary command, such as sending mail. Configure this daemon in /etc/tomoyo/tools/notifyd.conf. This makes it possible to be notified about policy violations as soon as possible, allowing subsequent action to be taken.
Start this program from an appropriate stage during startup (e.g. /etc/rc.local).
If you wish to freeze a process using the \*(C`time_to_wait\*(C' directive, you must register this program in /sys/kernel/security/tomoyo/manager.
time_to_wait 0 action_to_take mail -s Notification\040from\040tomoyo-notifyd root@localhost minimal_interval 60
See the configuration file for more information about the syntax.
If you find any bugs, send an email to <[email protected]>.
Main author.
Documentation and website.
See <http://tomoyo.sourceforge.jp> for more information.