* Add new per-packet access controls to SELinux, replacing the old packet controls. Packets are labeled with the iptables SECMARK and CONNSECMARK targets, then security policy for the packets is enforced with these controls. The old code is but not active by default - to restore previous behavior, the old controls may be activated at runtime by writing a '1' to /selinux/compat_net and also via the kernel boot parameter selinux_compat_net. Switching between the network control models

