~ubuntu-branches/ubuntu/natty/refpolicy-ubuntu/natty

« back to all changes in this revision

Viewing changes to policy/modules/services/snort.te

  • Committer: Bazaar Package Importer
  • Author(s): Caleb Case
  • Date: 2009-10-19 01:48:39 UTC
  • mfrom: (1.1.1 upstream)
  • Revision ID: james.westby@ubuntu.com-20091019014839-0rpi67ygkrjya30k
Tags: 0.2.20090730-0ubuntu1
* Updated to upstream release 2.20090730
* Handle Upstart direct execution of daemons.
* Pre-depend on selinux to ensure that the trigger is handled (LP: #434084).

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
 
2
 
policy_module(snort, 1.7.1)
 
2
policy_module(snort, 1.7.2)
3
3
 
4
4
########################################
5
5
#
56
56
files_pid_filetrans(snort_t, snort_var_run_t, file)
57
57
 
58
58
kernel_read_kernel_sysctls(snort_t)
 
59
kernel_read_sysctl(snort_t)
59
60
kernel_list_proc(snort_t)
60
61
kernel_read_proc_symlinks(snort_t)
61
62
kernel_dontaudit_read_system_state(snort_t)
70
71
corenet_raw_sendrecv_generic_node(snort_t)
71
72
corenet_tcp_sendrecv_all_ports(snort_t)
72
73
corenet_udp_sendrecv_all_ports(snort_t)
 
74
corenet_tcp_connect_prelude_port(snort_t)
73
75
 
74
76
dev_read_sysfs(snort_t)
75
77
dev_read_rand(snort_t)
90
92
miscfiles_read_localization(snort_t)
91
93
 
92
94
sysnet_read_config(snort_t)
 
95
# snorts must be able to resolve dns in case it wants to relay to a remote prelude-manager
 
96
sysnet_dns_name_resolve(snort_t)
93
97
 
94
98
userdom_dontaudit_use_unpriv_user_fds(snort_t)
95
99
userdom_dontaudit_search_user_home_dirs(snort_t)
96
100
 
97
101
optional_policy(`
 
102
        prelude_manage_spool(snort_t)
 
103
')
 
104
 
 
105
optional_policy(`
98
106
        seutil_sigchld_newrole(snort_t)
99
107
')
100
108