a49a82c295
Didn't rearrange all the kernel calls, but did add the kernel_request_load_module. Didn't include the usbmod (doesn't exist in refpolicy at this time). Included the generic usb device permissions because snort uses libpcap, which can also be used to monitor USB traffic, so this may be a side effect. From the red hat bug (559861), it sounds as though snort was failing without these permissions, so it doesn't look like a dontaudit would work. |
||
---|---|---|
.. | ||
flask | ||
modules | ||
support | ||
constraints | ||
global_booleans | ||
global_tunables | ||
mcs | ||
mls | ||
policy_capabilities | ||
rolemap | ||
users |