profile="/usr/lib/dovecot/auth" name="/run/dovecot/stats-user"
denied_mask="w"

That's already covered by the latest upstream profile.

profile="/usr/lib/dovecot/auth" name="/run/dovecot/anvil-auth-penalty" 
denied_mask="wr"
profile="/usr/lib/dovecot/auth" name="/var/spool/postfix/private/auth" 
denied_mask="w"

That translates to:
  /{var/,}run/dovecot/anvil-auth-penalty rw,
  /var/spool/postfix/private/auth w,

info="Failed name lookup - disconnected path" error=-13
profile="/usr/lib/dovecot/log"

You'll need to add   flags=(attach_disconnected)   to the dovecot/log
profile.


Patch sent to upstream mailinglist for review.

** Also affects: apparmor
   Importance: Undecided
       Status: New

** Changed in: apparmor
     Assignee: (unassigned) => Christian Boltz (cboltz)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1652131

Title:
  Putting Apparmor profile usr.lib.dovecot.auth into enforce mode blocks
  access to /var/spool/private/auth for Dovecot

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1652131/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to