tomoyo-queryd - real-time access request management utility for TOMOYO Linux
Contents
Bugs
If you find any bugs, send an email to <tomoyo-users-en@lists.osdn.me>.
Description
This program detects policy violations that occur in domains set to enforcing mode. The violation is
displayed and a number of options are given to either grant or reject this request. Programs are frozen
until a response is provided by the administrator.
This is useful when upgrading packages on the system, as errors due to changes in permissions can be
avoided.
Carefully analyze access requests before you grant them, as they could be coming from a compromised
process or malicious attacker.
Before this program can be invoked, you must register it in /sys/kernel/security/tomoyo/manager. After
initializing policy, this is usually as simple as rebooting the system.
Examples
Handlepolicyviolationsonthelocalsystem
tomoyo-queryd
Handlepolicyviolationsonaremotesystem
tomoyo-queryd 192.168.1.1:10000
Name
tomoyo-queryd - real-time access request management utility for TOMOYO Linux
Options
remote_ip:remote_port
Instead of managing local policy violations, manage remote policy via an agent waiting at port
remote_port on IP address remote_ip.
See Also
tomoyo-editpolicy-agent(8), tomoyo-notifyd(8) See <https://tomoyo.osdn.jp> for more information. tomoyo-tools 2.6.0 2019-02-05 TOMOYO-QUERYD(8)
Synopsis
tomoyo-querydtomoyo-queryd [remote_ip:remote_port]
