If enabled in the kernel configuration, RSBAC adds one directory to the main proc dir: /proc/rsbac-info. Since proc is treated as a normal read-only fs, rsbac could not be used.
All successful write accesses are logged via syslog at KERN_INFO level. The rsbac-info dir contains the following entries:
echo “devices no_write n:m k” > /proc/rsbac-info/devices
with n:m as the device in major:minor notation, k is 0 or 1.echo “no_write listname n” >versions
with listname is one of dev, user, log_levels, n is 0 or 1.echo “auto interval n” > /proc/rsbac-info/auto_write
with n = number of jiffies, debug level (0 or 1) by calling echo “auto debug n” > /proc/rsbac-info/auto_write
.echo “log_levels request n” > /proc/rsbac-info/log_levels
with request = request name, e.g. WRITE, n = level.cat rmsg
.echo “debug syslog_rate n” > /proc/rsbac_info/debug
echo “debug rmsg_maxentries n” > debug
echo “debug log_remote_maxentries n” > debug
echo “debug log_remote_addr a.b.c.d” >debug
echo “debug log_remote_port n” > /proc/rsbac-info/debug
.echo “debug name n” > /proc/rsbac-info/debug
. Valid names are ds, aef, auth, no_write, ds_pm, aef_pm, adf_pm, adf_ms, ds_rc, aef_rc, adf_rc, ds_acl, aef_acl, adf_acl, adf_auth, auto, softmode, dac_disable and nosyslog, but only, if shown when reading this file. Valid levels are 0 and 1.echo “debug ind_softmode <modname> n” >debug
echo “debug daz_ttl n” > /proc/rsbac-info/debug
echo “debug cap_log_missing n” >debug
echo “debug jail_log_missing n” >debug
Table of Contents: RSBAC Handbook