2010-02-23 20:56:40

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_snort.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F13/services_snort.patch

snort creates generic sockets
We can dontaudit read of system state

rearrage kernel calls and allow snort to request the kernel load a module.


uses usbmod and genrice usb devices.