I recently upgraded to the new imap package (thanks for
maintaining it Jaldhar!) and noticed a significant change in
lockfile management.

The imap daemon runs as the user/group of the person executing
the daemon instead of the group "mail".  This causes a problem
since I currently have the spool directory ownership/permissions
set to:

  drwxrwsr-t   root  mail    /var/spool/mail

My MUA (i.e. pine) warns that the mailbox is vulnerable since a
lockfile is not created.  What's strange is if I allow global
writes, no lockfile actually written but the MUA is happy.

What should be the ownership/permission of /var/spool/mail?  Or
should /usr/sbin/imapd be sgid mail?


Jean Pierre

