selinux-policy/policy
Jeremy Solt a49a82c295 snort patch from Dan Walsh
Didn't rearrange all the kernel calls, but did add the kernel_request_load_module.
Didn't include the usbmod (doesn't exist in refpolicy at this time).
Included the generic usb device permissions because snort uses libpcap, which can also be used to monitor USB traffic, so this may be a side effect.
From the red hat bug (559861), it sounds as though snort was failing without these permissions, so it doesn't look like a dontaudit would work.
2010-04-05 13:46:11 -04:00
..
flask Add module_request permission, from Dan Walsh. 2009-11-19 08:52:06 -05:00
modules snort patch from Dan Walsh 2010-04-05 13:46:11 -04:00
support add write to manage_lnk_file_perms. 2010-03-04 11:29:06 -05:00
constraints Fix a typo of SElinux to SELinux. 2009-10-22 09:47:52 -04:00
global_booleans trunk: merge strict and targeted policies. merge shlib_t into lib_t. 2007-10-02 16:04:50 +00:00
global_tunables remove read_default_t tunable 2009-07-23 08:58:35 -04:00
mcs revise MCS constraints to use only MCS-specific attributes. 2009-10-07 11:48:14 -04:00
mls Add back missing s0 on network_port(). 2010-03-08 07:59:56 -05:00
policy_capabilities trunk: update policycaps comments for sock_file open perm. 2009-07-01 13:34:54 +00:00
rolemap trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
users Typo in policy/users 2009-12-18 08:51:58 -05:00