Releases
Current version
Git/Latestdiff: 1.5.6
Latest Snapshots
Produced after each commit or rebase to new upstream version
GIT clone e.g. at git://git.rsbac.org/linux-6.18.y
Events
No events planned
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| documentation:proc_interface [2006/05/02 13:40] – (old revision restored) 127.0.0.1 | documentation:proc_interface [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== RSBAC Proc Interface ====== | ||
| - | If enabled in the kernel configuration, | ||
| - | main proc dir: rsbac-info. Since proc is treated as a normal read-only fs, | ||
| - | rsbac could not be used. | ||
| - | All successful write accesses are logged via syslog at KERN_INFO level. | ||
| - | The rsbac-info dir contains the following entries: | ||
| - | |||
| - | ===== Status ===== | ||
| - | * active: short summary of version, mode and module states, good for scripts | ||
| - | * stats: shows rsbac status, same contents as sys_rsbac_stats writes into syslog | ||
| - | * stats_pm (if PM is enabled): shows PM status, same contents as sys_rsbac_stats_pm writes into syslog | ||
| - | * stats_rc (if RC is enabled): shows RC status | ||
| - | * stats_auth (if AUTH is enabled): shows AUTH status | ||
| - | * stats_acl (if ACL is enabled): shows ACL status | ||
| - | * xstats (if extended status is enabled): shows extended status, e.g. table of call counts for requests and targets | ||
| - | * devices: shows all rsbac-mounted devices in n:m notation and their no_write status (no_write is set on fd-list read, if wrong version). No_write status can be changed by calling '' | ||
| - | * acl_devices, | ||
| - | * versions: shows aci versions for dev and user list and adf request array version for log_level array and the no_write status of each (set on boot, if wrong version is tried to be read). No_write status can be changed by calling '' | ||
| - | |||
| - | ===== System Behaviour ===== | ||
| - | |||
| - | * auto_write (if auto-write is enabled): shows auto write status, currently auto interval in jiffies and auto debug level only. Auto interval can be changed by calling '' | ||
| - | |||
| - | ===== Logging ===== | ||
| - | |||
| - | * log_levels: shows adf log levels for all requests. Log levels can be changed by calling '' | ||
| - | * rmsg (if own logging is enabled): similar to kmsg in main proc dir, logging of RSBAC requests. This file can be used by programs like klogd, or simply make a '' | ||
| - | |||
| - | ===== Model Specific ===== | ||
| - | |||
| - | * auth_caplist (if AUTH is enabled): shows all AUTH capabilities currently set. | ||
| - | * reg_modules (if REG is enabled): shows currently registered additional decision modules and syscalls. | ||
| - | * acl_acllist (if ACL is enabled): Detailed listing of all ACL entries and masks in the system. | ||
| - | |||
| - | ===== Debug and Softmode Switching ===== | ||
| - | * debug: shows all RSBAC debug settings, softmode, dac_disable and nosyslog. | ||
| - | * Levels can be changed by calling '' | ||
| - | * Debug levels can be preset to 1 by kernel parameters with same name as variable name shown, e.g. rsbac_debug_ds or rsbac_softmode. | ||
| - | * Individual model softmode can be switched by calling '' | ||
| - | * Remote logging address and port can be changed with '' | ||
| - | * DAZ cache ttl is set via '' | ||
| - | * CAP log missing is set with '' | ||
| - | * JAIL log missing (new in 1.2.5) is set with '' | ||
| - | |||
| - | ===== Backups ===== | ||
| - | |||
| - | * backup subdir: It contains backups of what would be current aci data files. You can use cp for backups of system independent aci data structures, e.g. rc_roles, rc_types, and the admin backup tools for system dependent ones, e.g. file/dir attributes or AUTH file capabilities. Using the backup_all script or single lines from it is however strongly recommended. | ||