Merge Dovecot profile: Allow reading of /proc/sys/kernel/core_pattern

See <https://dovecot.org/bugreport.html>

(the link describes how Dovecot requires access to `core_pattern`)

MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/1331
Approved-by: Christian Boltz <apparmor@cboltz.de>
Merged-by: Christian Boltz <apparmor@cboltz.de>
This commit is contained in:
Christian Boltz 2024-11-21 20:51:13 +00:00
commit 2b45586fa9

View file

@ -45,6 +45,7 @@ profile dovecot /usr/{bin,sbin}/dovecot flags=(attach_disconnected) {
/etc/SuSE-release r, /etc/SuSE-release r,
@{PROC}/@{pid}/mounts r, @{PROC}/@{pid}/mounts r,
@{PROC}/sys/fs/suid_dumpable r, @{PROC}/sys/fs/suid_dumpable r,
@{PROC}/sys/kernel/core_pattern r,
/usr/bin/doveconf rix, /usr/bin/doveconf rix,
/usr/lib*/dovecot/anvil mrPx, /usr/lib*/dovecot/anvil mrPx,
/usr/lib*/dovecot/auth mrPx, /usr/lib*/dovecot/auth mrPx,