aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKenton Groombridge <me@concord.sh>2021-10-13 13:36:25 -0400
committerJason Zaman <perfinion@gentoo.org>2021-11-20 14:58:24 -0800
commit89cbc037a65cd4e6871a32337bb9f0e1c1f4dc95 (patch)
treeef679b12f348b5678e806a949757719bdd355dde /policy/modules/services/postfix.te
parentmcs: combine single-level object creation constraints (diff)
downloadhardened-refpolicy-89cbc037a65cd4e6871a32337bb9f0e1c1f4dc95.tar.gz
hardened-refpolicy-89cbc037a65cd4e6871a32337bb9f0e1c1f4dc95.tar.bz2
hardened-refpolicy-89cbc037a65cd4e6871a32337bb9f0e1c1f4dc95.zip
various: deprecate mcs override interfaces
Signed-off-by: Kenton Groombridge <me@concord.sh> Signed-off-by: Jason Zaman <perfinion@gentoo.org>
Diffstat (limited to 'policy/modules/services/postfix.te')
-rw-r--r--policy/modules/services/postfix.te10
1 files changed, 0 insertions, 10 deletions
diff --git a/policy/modules/services/postfix.te b/policy/modules/services/postfix.te
index 98416368..b6a9bb6b 100644
--- a/policy/modules/services/postfix.te
+++ b/policy/modules/services/postfix.te
@@ -292,8 +292,6 @@ domain_use_interactive_fds(postfix_master_t)
files_search_tmp(postfix_master_t)
-mcs_file_read_all(postfix_master_t)
-
term_dontaudit_search_ptys(postfix_master_t)
hostname_exec(postfix_master_t)
@@ -568,9 +566,6 @@ allow postfix_pickup_t postfix_spool_maildrop_t:dir list_dir_perms;
read_files_pattern(postfix_pickup_t, postfix_spool_maildrop_t, postfix_spool_maildrop_t)
delete_files_pattern(postfix_pickup_t, postfix_spool_maildrop_t, postfix_spool_maildrop_t)
-mcs_file_read_all(postfix_pickup_t)
-mcs_file_write_all(postfix_pickup_t)
-
optional_policy(`
dbus_system_bus_client(postfix_pickup_t)
init_dbus_chat(postfix_pickup_t)
@@ -639,9 +634,6 @@ allow postfix_postdrop_t postfix_local_t:unix_stream_socket { read write };
# for /var/spool/postfix/public/pickup
stream_connect_pattern(postfix_postdrop_t, postfix_public_t, postfix_public_t, postfix_master_t)
-mcs_file_read_all(postfix_postdrop_t)
-mcs_file_write_all(postfix_postdrop_t)
-
term_dontaudit_use_all_ptys(postfix_postdrop_t)
term_dontaudit_use_all_ttys(postfix_postdrop_t)
@@ -747,8 +739,6 @@ allow postfix_showq_t postfix_spool_maildrop_t:lnk_file read_lnk_file_perms;
allow postfix_showq_t postfix_spool_t:file read_file_perms;
-mcs_file_read_all(postfix_showq_t)
-
term_use_all_ptys(postfix_showq_t)
term_use_all_ttys(postfix_showq_t)