mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 16:35:02 +01:00

- allow /var/spool/mail, not only the /var/mail symlink - allow @{HOME}/Mail/ - allow capability fsetid, read access to /etc/lsb-release and SuSE-release and k for /var/{lib,run}/dovecot in usr.bin.dovecot References: - dovecot: Added support for /var/spool/mail (bnc#691072) - Updated dovecot profile (bnc#681267). Patch taken from openSUSE:11.4:Update:Test, file apparmor-profiles-dovecot updated to match trunk by Christian Boltz <apparmor@cboltz.de> Change compared to the patch posted to the ML: - link rule instead of adding l permissions for /var/lib/dovecot and /var/run/dovecot (as proposed by John Johansen) Acked-By: John Johansen <john.johansen@canonical.com> on IRC
24 lines
594 B
Text
24 lines
594 B
Text
# Author: Dulmandakh Sukhbaatar <dulmandakh@gmail.com>
|
|
|
|
#include <tunables/global>
|
|
/usr/lib/dovecot/deliver {
|
|
#include <abstractions/base>
|
|
#include <abstractions/nameservice>
|
|
|
|
capability setgid,
|
|
capability setuid,
|
|
|
|
/etc/dovecot/dovecot-postfix.conf r,
|
|
@{HOME} r,
|
|
@{HOME}/Maildir/ rw,
|
|
@{HOME}/Maildir/** klrw,
|
|
@{HOME}/mail/ rw,
|
|
@{HOME}/mail/* klrw,
|
|
@{HOME}/mail/.imap/** klrw,
|
|
/usr/lib/dovecot/deliver mr,
|
|
/var/mail/* klrw,
|
|
/var/spool/mail/* klrw,
|
|
|
|
# Site-specific additions and overrides. See local/README for details.
|
|
#include <local/usr.lib.dovecot.deliver>
|
|
}
|