Bump for #382851, thanks to Jason Wallace
authorPatrick Lauer <patrick@gentoo.org>
Thu, 22 Sep 2011 17:39:51 +0000 (17:39 +0000)
committerPatrick Lauer <patrick@gentoo.org>
Thu, 22 Sep 2011 17:39:51 +0000 (17:39 +0000)
Package-Manager: portage-2.2.0_alpha59/cvs/Linux x86_64

net-analyzer/snort/ChangeLog
net-analyzer/snort/Manifest
net-analyzer/snort/files/snort.confd.2 [new file with mode: 0644]
net-analyzer/snort/files/snort.rc11 [new file with mode: 0644]
net-analyzer/snort/metadata.xml
net-analyzer/snort/snort-2.9.1.ebuild [new file with mode: 0644]

index 9effb5714c6f471416bba4ca014da6a50f39ee92..c078299f66c214402da1f232634e03093a6e8ca3 100644 (file)
@@ -1,6 +1,12 @@
 # ChangeLog for net-analyzer/snort
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-analyzer/snort/ChangeLog,v 1.185 2011/09/21 15:33:43 chainsaw Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-analyzer/snort/ChangeLog,v 1.186 2011/09/22 17:39:51 patrick Exp $
+
+*snort-2.9.1 (22 Sep 2011)
+
+  22 Sep 2011; Patrick Lauer <patrick@gentoo.org> +snort-2.9.1.ebuild,
+  +files/snort.confd.2, +files/snort.rc11, metadata.xml:
+  Bump for #382851, thanks to Jason Wallace
 
   21 Sep 2011; Tony Vroon <chainsaw@gentoo.org> snort-2.9.0.5.ebuild:
   Marked stable on AMD64 based on arch testing by Agostino "ago" Sarubbo &
index 1a3d0ffab4bf0a849c7d91928cfa51e48f36edaa..b4141f153d55cd4388cbd50d66d308becf17a161 100644 (file)
@@ -1,11 +1,10 @@
------BEGIN PGP SIGNED MESSAGE-----
-Hash: SHA1
-
 AUX disabledynamic.patch 4189 RMD160 e24db349742b5885206466ee0254457f69a18272 SHA1 63388be21fefb841740a2dd0df7684ad24f2dc40 SHA256 018cec1ffab83b65506478e33c51f26aeaddab3152a1c5c1d5b4f0952ac00fd4
 AUX pcap_memory.patch 563 RMD160 3d4ed78ee4588e09401753026e6766ebcf290743 SHA1 962cb1379af8a382cb31ac07fe21614bbe6e3f8b SHA256 fc73d20c8b414decaba2cccdb50168489e84ddf906cf3c1e9490235a15f3e065
 AUX snort-2.8.4-libnet.patch 9037 RMD160 76854b43712d9d5375263ee4aeba7161658bba6b SHA1 24ff2aa83a680c158be7876acc88cb4f47ffd85f SHA256 4659a2e141e476b7dfcb627de3c8dc884014e601a9fd9fe57e4d0c0912193650
 AUX snort.confd 442 RMD160 439e885d43aacc474c41eeed5217a498b2917aac SHA1 87a3de61e218367b2239540b94c564b2c6729300 SHA256 40adf5e7b918d1feae6728c1445e879d4cc478f81d13e9f32a2de1be1345413a
+AUX snort.confd.2 420 RMD160 66bead70bfb5752d7f9779803453bdecf2694fee SHA1 d4917da66def50d09430a0dff4b2e86103a4834a SHA256 337378f098e0cd59fb5c28a26b5b74b32168cf48596064469e6a5ba04fe3a36f
 AUX snort.rc10 1184 RMD160 e21154f031671a49c421da880ce3f56637147fbf SHA1 15b6214672e8c4512faa98e2fdd11e383e0d671b SHA256 268051b41011af92341d996105b820115089828be56d664301a662da396007ad
+AUX snort.rc11 1473 RMD160 f9d1a9bfbe88b0bcb5dbecbab3ee3fc647f0a9ff SHA1 cf97f12c9560b85d6ac12492020c5222eb4613b3 SHA256 280ed4fb18c871ca83469a4dd1485f47d422b9d4476613711707c627176e4774
 AUX snort.rc9 849 RMD160 d031761fff4cf8f7bc28a465d3b5ecc740579e21 SHA1 8c16b1f7f064ebf962ad469b55e5a6738939b8e4 SHA256 585c6e96fc2265861436347ddf52d44c1c049fe7083825e16253f7717c968ec4
 AUX snort.reload.rc1 1190 RMD160 cbe18ddc93f3091f0faef317d96211b8d7d3798d SHA1 f7b4aff2b7b25b1c8d5886e1fab63856e1ccfe06 SHA256 c6af6ff89034872a7192af360a24de811aeba7fb06704ebe758eea9dcde933e9
 DIST snort-2.8.5.1.tar.gz 4715078 RMD160 fbfab45f1d7d815516043592eab8cf1cc6ec93d0 SHA1 b971052cdd4b3527a0603854953103fe9ad8a45b SHA256 ade1b0f4ae74fd623c633d28b6f1429187751b35b36a3f8a0c197d2104b5e5ae
@@ -14,18 +13,13 @@ DIST snort-2.8.6.1.tar.gz 4939019 RMD160 27925c0df9debc9e60e19a0c989db28c8d1ca7f
 DIST snort-2.8.6.tar.gz 4960740 RMD160 5b549eab39a6e0a0f182f6d2ee46fd60995c822e SHA1 e463c99994e52171439623e1b05b9e1bcf01ac8f SHA256 6064d7bb78d6438b455ff349b93d52f40d3977f1fecb1d7958c87881b0030358
 DIST snort-2.9.0.4-r1.tar.gz 5812096 RMD160 e33ff54d72334413cf7970c418370e4f8a953c9e SHA1 a803fae561f829c2dad7e61f0a9b8f75f72356de SHA256 053d1562f4ffc1793188f0d2475c043ddae42b33f8b93be45d7e67dbc7424b8d
 DIST snort-2.9.0.5.tar.gz 5867934 RMD160 668c586c8cfab905c18af08ca6b61b96dddb398a SHA1 b4565d3a8387f6b5e7aceb3aee80803ceabf80f2 SHA256 f997fddbbd1a5f7ccdd4153610b0916fcbe105ea3316d4ed3487fd0054287e94
+DIST snort-2.9.1.tar.gz 6217639 RMD160 81070dd6b18f106368473c396d82261e7db1dc3d SHA1 b1ae80bbfd9145cae89c6249f4b5176fbccbf90d SHA256 1e69de95c8956191b26d19138a2fb7b6f2faf519f601aa3c7d779593c48830c2
 EBUILD snort-2.8.5.1.ebuild 10255 RMD160 c20884731d63f87fda08c4cefc27032f32a45fcc SHA1 78fba4dd7e17177071fcfc043c6d268dfd1c0fe1 SHA256 4712367f62d48e94d0ada7c53e1902e2b9215f990b176186f80d9513dee43e81
 EBUILD snort-2.8.5.3.ebuild 10255 RMD160 8664ac1012b5cd104fcef298a29c6e7e2f33e4fa SHA1 efc68f670381a50fea54ebac6ed49447732340c6 SHA256 88ed50e2f114af64e037fdf62d7ffbcf8d52a6fd8b632bbd482e3b458b1ba1ed
 EBUILD snort-2.8.6.1.ebuild 10453 RMD160 7028aad5e61746e33a6f87134f33a074ae8424c8 SHA1 ac13164766e99b9efb8b564b980bd09e08f6738d SHA256 3703979c75830d335cd03a77fd68b85e001f586c6c598b05e84648ee35994809
 EBUILD snort-2.8.6.ebuild 10130 RMD160 c2b00348106ddd42fd1d85e81379172a967f362e SHA1 2da5ff9240446e00237e8fe81a1001d85d20d1e3 SHA256 8788b91ef4b8ad8b6e3ca7bcb456afa94f497b454a3098201c977c0e0f6584a6
 EBUILD snort-2.9.0.4-r1.ebuild 9893 RMD160 d2c79206d777528bf798737d53f4d3b8cfcbff3c SHA1 c20ce779028cb97368fcaff15443abeff38c04b3 SHA256 33abee6ef5d662cb3854f268cf3dd596a281b2c10b5d15e87f5ac2cc7204e815
 EBUILD snort-2.9.0.5.ebuild 10179 RMD160 1bff0dc4e6489fbefd6452fe27743f9b092efd55 SHA1 c742d26a91a26007d523f6cc2fb45e6948422ff3 SHA256 72c4194ee295d96529f6d6d30a12bc3b60f3a312a3a59cc0983fdc9e24195d37
-MISC ChangeLog 32156 RMD160 8a18b0adfa4722b23667927a6c4254dc64946c90 SHA1 d9a531b829164aac034dd033ceb4422bc0da1c31 SHA256 accb6ac7e2e0355770243646aa863503a703ed1ab676596e5c8261dc0be9a03d
-MISC metadata.xml 5174 RMD160 3de62ad1395938c61f8ea10bf91b816687fd2fc2 SHA1 83c1ced9279fcd14b378bcafc316b255b7932667 SHA256 5e2577560aaf444e1699aa796a8126276222ddd413289d72aea3c35dfdfbb2cb
------BEGIN PGP SIGNATURE-----
-Version: GnuPG v2.0.18 (GNU/Linux)
-
-iEYEARECAAYFAk56A+IACgkQp5vW4rUFj5oX9gCfXiNOKDAF6qMp7zHsj3oyS6DJ
-HC4An0CGXqpchm8MLrBwxa4HDfRzoYio
-=Kf6l
------END PGP SIGNATURE-----
+EBUILD snort-2.9.1.ebuild 9292 RMD160 dcd3cca120a07e5bb7c8bb2da794f80d0ec14604 SHA1 1d35c11b6d7e2dd60b11e4182803d5e0bdc16999 SHA256 11d5057f8c69411eb8135b7046a8bbba67f84d541a6963528e07fca3878fa4e9
+MISC ChangeLog 32356 RMD160 d6bea8bd3762dd6ad670a6865af83e6e2c0763eb SHA1 3ebb6e5e10ef9b7a36d10ad1319a01d1b67d360f SHA256 875eb6e5482dbc50d008f50f1f77740c56f3c830b8ca78e690e6a42e9cb655f3
+MISC metadata.xml 5524 RMD160 d307f40c1dfece37a0bf5bdc9264141bdd86f61a SHA1 0b88ce23a95d7c96ffb15609761d143c64ba1c10 SHA256 621972507e7e2d501d947c4acefc1d5a700173171f95d838a675bcfca135251d
diff --git a/net-analyzer/snort/files/snort.confd.2 b/net-analyzer/snort/files/snort.confd.2
new file mode 100644 (file)
index 0000000..780c910
--- /dev/null
@@ -0,0 +1,16 @@
+# Config file for /etc/init.d/snort
+
+# The following options are now set in your snort.conf file:
+# config set_gid:
+# config set_uid:
+# config snaplen:
+# config bpf_file:
+# config logdir:
+
+# The only options that should be set here are SNORT_IFACE and SNORT_CONF.
+
+# This tell snort which interface to listen on (any for every interface)
+SNORT_IFACE="eth1"
+
+# Probably not this either
+SNORT_CONF="/etc/snort/snort.conf"
diff --git a/net-analyzer/snort/files/snort.rc11 b/net-analyzer/snort/files/snort.rc11
new file mode 100644 (file)
index 0000000..8277575
--- /dev/null
@@ -0,0 +1,57 @@
+#!/sbin/runscript
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-analyzer/snort/files/snort.rc11,v 1.1 2011/09/22 17:39:51 patrick Exp $
+
+opts="checkconfig reload"
+
+depend() {
+       need net
+       after mysql
+       after postgresql
+}
+
+checkconfig() {
+       if [ ! -e ${SNORT_CONF} ] ; then
+               eerror "You need a configuration file to run snort"
+               eerror "There is an example config in /etc/snort/snort.conf.distrib"
+               return 1
+       fi
+}
+
+start() {
+       checkconfig || return 1
+       ebegin "Starting snort"
+       start-stop-daemon --start --quiet --exec /usr/bin/snort \
+               -- --nolock-pidfile --pid-path /var/run/snort -D -i ${SNORT_IFACE} \
+                -c ${SNORT_CONF} >/dev/null 2>&1
+       eend $?
+}
+
+stop() {
+       ebegin "Stopping snort"
+       start-stop-daemon --stop --quiet --pidfile /var/run/snort/snort_${SNORT_IFACE}.pid
+       # Snort needs a few seconds to fully shutdown
+       sleep 15
+       eend $?
+}
+
+reload() {
+
+       local SNORT_PID="`cat /var/run/snort/snort_${SNORT_IFACE}.pid`"
+       local SNORT_USER="`ps -p ${SNORT_PID} --no-headers -o user`"
+
+        if [ ! -f /var/run/snort/snort_${SNORT_IFACE}.pid ]; then
+               eerror "Snort isn't running"
+                return 1
+       elif [ ${SNORT_USER} != root ]; then
+               eerror "Snort must be running as root for reload to work!"
+               return 1
+       else
+               checkconfig || return 1
+               ebegin "Reloading Snort"
+               start-stop-daemon --signal HUP --pidfile /var/run/snort/snort_${SNORT_IFACE}.pid
+        fi
+}
+
+
index c4b73b613d323dc56c15fc53099608e548704056..9e977f34dd2125811a5655a037febdce03487fab 100644 (file)
                        connection tearing for inline deployments. Replaces flexresp and \r
                        flexresp2.\r
                </flag>\r
+               <flag name='paf'>\r
+                       Enables support for Protocol Aware Flushing. This allows Snort to\r
+                       statefully scan a stream and reassemble a complete protocol data\r
+                       unit regardless of segmentation.\r
+               </flag>\r
+               <flag name='large-pcap-64bit'>\r
+                       Allows Snort to read pcap files that are larger than 2 GB. ONLY\r
+                       VALID FOR 64bit SYSTEMS!\r
+               </flag>\r
        </use>\r
 </pkgmetadata>\r
diff --git a/net-analyzer/snort/snort-2.9.1.ebuild b/net-analyzer/snort/snort-2.9.1.ebuild
new file mode 100644 (file)
index 0000000..d1c8b67
--- /dev/null
@@ -0,0 +1,264 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-analyzer/snort/snort-2.9.1.ebuild,v 1.1 2011/09/22 17:39:51 patrick Exp $
+
+EAPI="2"
+inherit eutils autotools multilib
+
+DESCRIPTION="The de facto standard for intrusion detection/prevention"
+HOMEPAGE="http://www.snort.org/"
+SRC_URI="http://www.snort.org/downloads/1107 -> ${P}.tar.gz"
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+IUSE="static +dynamicplugin +zlib +gre +mpls +targetbased +decoder-preprocessor-rules
++ppm +perfprofiling linux-smp-stats inline-init-failopen +threads debug +active-response
++normalizer reload-error-restart +react +flexresp3 +paf large-pcap-64bit
+aruba mysql odbc postgres selinux"
+
+DEPEND=">=net-libs/libpcap-1.0.0
+       >=net-libs/daq-0.5
+       >=dev-libs/libpcre-6.0
+       dev-libs/libdnet
+       postgres? ( dev-db/postgresql-base )
+       mysql? ( virtual/mysql )
+       odbc? ( dev-db/unixODBC )
+       zlib? ( sys-libs/zlib )"
+
+RDEPEND="${DEPEND}
+       selinux? ( sec-policy/selinux-snort )"
+
+pkg_setup() {
+
+       if use zlib && ! use dynamicplugin; then
+               eerror "You have enabled the 'zlib' USE flag but not the 'dynamicplugin' USE flag."
+               eerror "'zlib' requires 'dynamicplugin' be enabled."
+               die
+       fi
+
+       # pre_inst() is a better place to put this
+       # but we need it here for the 'fowners' statements in src_install()
+       enewgroup snort
+       enewuser snort -1 -1 /dev/null snort
+
+}
+
+src_prepare() {
+
+       #Multilib fix for the sf_engine
+       einfo "Applying multilib fix."
+       sed -i -e 's|${exec_prefix}/lib|${exec_prefix}/'$(get_libdir)'|g' \
+               "${WORKDIR}/${P}/src/dynamic-plugins/sf_engine/Makefile.am" \
+               || die "sed for sf_engine failed"
+
+       #Multilib fix for the curent set of dynamic-preprocessors
+       for i in ftptelnet smtp ssh dns ssl dcerpc2 sdf imap pop rzb_saac sip reputation; do
+               sed -i -e 's|${exec_prefix}/lib|${exec_prefix}/'$(get_libdir)'|g' \
+                       "${WORKDIR}/${P}/src/dynamic-preprocessors/$i/Makefile.am" \
+                       || die "sed for $i failed."
+       done
+
+       AT_M4DIR=m4 eautoreconf
+}
+
+src_configure() {
+
+       econf \
+               $(use_enable !static shared) \
+               $(use_enable static) \
+               $(use_enable static so-with-static-lib) \
+               $(use_enable dynamicplugin) \
+               $(use_enable zlib) \
+               $(use_enable gre) \
+               $(use_enable mpls) \
+               $(use_enable targetbased) \
+               $(use_enable decoder-preprocessor-rules) \
+               $(use_enable ppm) \
+               $(use_enable perfprofiling) \
+               $(use_enable linux-smp-stats) \
+               $(use_enable inline-init-failopen) \
+               $(use_enable threads pthread) \
+               $(use_enable debug) \
+               $(use_enable debug debug-msgs) \
+               $(use_enable debug corefiles) \
+               $(use_enable !debug dlclose) \
+               $(use_enable active-response) \
+               $(use_enable normalizer) \
+               $(use_enable reload-error-restart) \
+               $(use_enable react) \
+               $(use_enable flexresp3) \
+               $(use_enable paf) \
+               $(use_enable large-pcap-64bit large-pcap) \
+               $(use_enable aruba) \
+               $(use_with mysql) \
+               $(use_with odbc) \
+               $(use_with postgres postgresql) \
+               --enable-ipv6 \
+               --enable-reload \
+               --disable-prelude \
+               --disable-build-dynamic-examples \
+               --disable-profile \
+               --disable-ppm-test \
+               --disable-intel-soft-cpm \
+               --disable-static-daq \
+               --disable-rzb-saac \
+               --without-oracle
+}
+
+src_install() {
+
+       emake DESTDIR="${D}" install || die "emake failed"
+
+       dodir /var/log/snort \
+               /var/run/snort \
+               /etc/snort/rules \
+               /etc/snort/so_rules \
+               /usr/$(get_libdir)/snort_dynamicrules \
+                       || die "Failed to create core directories"
+
+       # config.log and build.log are needed by Sourcefire
+       # to trouble shoot build problems and bug reports so we are
+       # perserving them incase the user needs upstream support.
+       dodoc RELEASE.NOTES ChangeLog \
+               doc/* \
+               tools/u2boat/README.u2boat \
+               schemas/* || die "Failed to install snort docs"
+
+       insinto /etc/snort
+       doins etc/attribute_table.dtd \
+               etc/classification.config \
+               etc/gen-msg.map \
+               etc/reference.config \
+               etc/threshold.conf \
+               etc/unicode.map || die "Failed to install docs in etc"
+
+       # We use snort.conf.distrib because the config file is complicated
+       # and the one shipped with snort can change drastically between versions.
+       # Users should migrate setting by hand and not with etc-update.
+       newins etc/snort.conf snort.conf.distrib \
+               || die "Failed to add snort.conf.distrib"
+
+       # config.log and build.log are needed by Sourcefire
+       # to troubleshoot build problems and bug reports so we are
+       # perserving them incase the user needs upstream support.
+       # 'die' was intentionally not added here.
+       if [ -f "${WORKDIR}/${PF}/config.log" ]; then
+               dodoc "${WORKDIR}/${PF}/config.log"
+       fi
+       if [ -f "${T}/build.log" ]; then
+               dodoc "${T}/build.log"
+       fi
+
+       insinto /etc/snort/preproc_rules
+       doins preproc_rules/decoder.rules \
+               preproc_rules/preprocessor.rules \
+               preproc_rules/sensitive-data.rules || die "Failed to install preproc rule files"
+
+       fowners -R snort:snort \
+               /var/log/snort \
+               /var/run/snort \
+               /etc/snort || die
+
+       newinitd "${FILESDIR}/snort.rc11" snort || die "Failed to install snort init script"
+       newconfd "${FILESDIR}/snort.confd.2" snort || die "Failed to install snort confd file"
+
+       # Sourcefire uses Makefiles to install docs causing Bug #297190.
+       # This removes the unwanted doc directory and rogue Makefiles.
+       rm -rf "${D}"usr/share/doc/snort || die "Failed to remove SF doc directories"
+       rm "${D}"usr/share/doc/"${PF}"/Makefile* || die "Failed to remove doc make files"
+
+       #Remove unneeded .la files (Bug #382863)
+       rm "${D}"usr/lib64/snort_dynamicengine/libsf_engine.la || die
+       rm "${D}"usr/lib64/snort_dynamicpreprocessor/libsf_*_preproc.la || die "Failed to remove libsf_?_preproc.la"
+
+       # Set the correct lib path for dynamicengine, dynamicpreprocessor, and dynamicdetection
+       sed -i -e 's|/usr/local/lib|/usr/'$(get_libdir)'|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the correct rule location in the config
+       sed -i -e 's|RULE_PATH ../rules|RULE_PATH /etc/snort/rules|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the correct preprocessor/decoder rule location in the config
+       sed -i -e 's|PREPROC_RULE_PATH ../preproc_rules|PREPROC_RULE_PATH /etc/snort/preproc_rules|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Enable the preprocessor/decoder rules
+       sed -i -e 's|^# include $PREPROC_RULE_PATH|include $PREPROC_RULE_PATH|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       sed -i -e 's|^# dynamicdetection directory|dynamicdetection directory|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Just some clean up of trailing /'s in the config
+       sed -i -e 's|snort_dynamicpreprocessor/$|snort_dynamicpreprocessor|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Make it clear in the config where these are...
+       sed -i -e 's|^include classification.config|include /etc/snort/classification.config|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       sed -i -e 's|^include reference.config|include /etc/snort/reference.config|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Disable all rule files by default. 
+       sed -i -e 's|^include $RULE_PATH|# include $RULE_PATH|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Disable normalizer preprocessor config if normalizer USE flag not set.
+       if ! use normalizer; then
+               sed -i -e 's|^preprocessor normalize|#preprocessor normalize|g' \
+                       "${D}etc/snort/snort.conf.distrib" || die
+       fi
+
+       # Set the configured DAQ to afpacket
+       sed -i -e 's|^# config daq: <type>|config daq: afpacket|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the location of the DAQ modules
+       sed -i -e 's|^# config daq_dir: <dir>|config daq_dir: /usr/'$(get_libdir)'/daq|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the DAQ mode to passive
+       sed -i -e 's|^# config daq_mode: <mode>|config daq_mode: passive|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set snort to run as snort:snort
+       sed -i -e 's|^# config set_gid:|config set_gid: snort|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+       sed -i -e 's|^# config set_uid:|config set_uid: snort|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the default log dir
+       sed -i -e 's|^# config logdir:|config logdir: /var/log/snort/|g' \
+               "${D}etc/snort/snort.conf.distrib" || die
+
+       # Set the correct so_rule location in the config
+        sed -i -e 's|SO_RULE_PATH ../so_rules|SO_RULE_PATH /etc/snort/so_rules|g' \
+                "${D}etc/snort/snort.conf.distrib" || die
+}
+
+pkg_postinst() {
+
+       einfo "There have been a number of improvements and new features"
+       einfo "added to ${P}. Please review the RELEASE.NOTES and"
+       einfo "ChangLog located in /usr/share/doc/${PF}."
+       einfo
+       elog "The Sourcefire Vulnerability Research Team (VRT) recommends that"
+       elog "users migrate their snort.conf customizations to the latest config"
+       elog "file released by the VRT. You can find the latest version of the"
+       elog "Snort config file in /etc/snort/snort.conf.distrib."
+       elog
+       elog "!! It is important that you migrate to this new snort.conf file !!"
+       elog
+       elog "This version of the ebuild includes an updated init.d file and"
+       elog "conf.d file that rely on options found in the latest Snort"
+       elog "config file provided by the VRT."
+
+       if use debug; then
+               elog "You have the 'debug' USE flag enabled. If this has been done to"
+               elog "troubleshoot an issue by producing a core dump or a back trace,"
+               elog "then you need to also ensure the FEATURES variable in make.conf"
+               elog "contains the 'nostrip' option."
+       fi
+}