Scroll to navigation

FAGENRULES(8) System Administration Utilities FAGENRULES(8)

NAME

fagenrules - a script that merges component fapolicyd rule files

SYNOPSIS

fagenrules [--check] [--load]

DESCRIPTION

fagenrules is a script that merges all component fapolicyd rules files, found in the fapolicyd rules directory, /etc/fapolicyd/rules.d, placing the merged file in /etc/fapolicyd/compiled.rules. Component fapolicyd rule files, must end in .rules in order to be processed. All other files in /etc/fapolicyd/rules.d are ignored.

The files are concatenated in order, based on their natural sort (see -v option of ls(1)) and stripped of empty and comment (#) lines.

The generated file is validated with the daemon policy parser before installation. If it differs from the existing compiled rules, it is synced and atomically renamed into /etc/fapolicyd/compiled.rules so the previous compiled rules remain in place on validation or installation failure.

fagenrules prints the final SHA-256 ruleset identity when the installed compiled rules are unchanged or successfully updated.

OPTIONS

test if rules have changed and need updating without overwriting compiled.rules.
load old or newly built rules into the daemon.

FILES

/etc/fapolicyd/rules.d/ /etc/fapolicyd/compiled.rules

SEE ALSO

fapolicyd.rules(5), fapolicyd-cli(8), fapolicyd(8).

Nov 2021 Red Hat