This bug is to let others know I'm taking a stab at refactoring the mail infrastructure domains (currently provided through the mta module). The idea is to introduce the mail_*_agent (MUA, MTA, MRA, MDA and MSA) domains and interact with those. The intermediate sendmail domain (currently created through user_mail_t or system_mail_t) will be rewritten and will optionally contain the privileges of the implementing technology. A mail_selinux manual page will be created explaining the new policy in detail. A stub mta will be provided. Reproducible: Always
Dropping this for a while. It works pretty well, but will not be accepted by upstream. I'll probably make this open later as part of a more global policy draft. But for now marking this as WONTFIX as it is not pressing for Gentoo.