diff --git a/policy/flask/access_vectors b/policy/flask/access_vectors index ffe6ca0ee..69f69af80 100644 --- a/policy/flask/access_vectors +++ b/policy/flask/access_vectors @@ -990,9 +990,6 @@ inherits socket class netrom_socket inherits socket -class bridge_socket -inherits socket - class atmpvc_socket inherits socket @@ -1020,12 +1017,6 @@ inherits socket class llc_socket inherits socket -class ib_socket -inherits socket - -class mpls_socket -inherits socket - class can_socket inherits socket diff --git a/policy/flask/security_classes b/policy/flask/security_classes index be94e9a22..18f18fd8e 100644 --- a/policy/flask/security_classes +++ b/policy/flask/security_classes @@ -159,7 +159,6 @@ class icmp_socket class ax25_socket class ipx_socket class netrom_socket -class bridge_socket class atmpvc_socket class x25_socket class rose_socket @@ -169,8 +168,6 @@ class rds_socket class irda_socket class pppox_socket class llc_socket -class ib_socket -class mpls_socket class can_socket class tipc_socket class bluetooth_socket diff --git a/policy/policy_capabilities b/policy/policy_capabilities index 103420ee5..39e393013 100644 --- a/policy/policy_capabilities +++ b/policy/policy_capabilities @@ -54,7 +54,6 @@ policycap open_perms; # ax25_socket # ipx_socket # netrom_socket -# bridge_socket # atmpvc_socket # x25_socket # rose_socket @@ -64,8 +63,6 @@ policycap open_perms; # irda_socket # pppox_socket # llc_socket -# ib_socket -# mpls_socket # can_socket # tipc_socket # bluetooth_socket diff --git a/policy/support/obj_perm_sets.spt b/policy/support/obj_perm_sets.spt index 0adce3225..1d21fd0f1 100644 --- a/policy/support/obj_perm_sets.spt +++ b/policy/support/obj_perm_sets.spt @@ -34,7 +34,7 @@ define(`devfile_class_set', `{ blk_file chr_file }') # # All socket classes. # -define(`socket_class_set', `{ tcp_socket udp_socket rawip_socket netlink_socket packet_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket bridge_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket ib_socket mpls_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket}') +define(`socket_class_set', `{ tcp_socket udp_socket rawip_socket netlink_socket packet_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket}') # # Datagram socket classes.