mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-31 14:25:52 +00:00
Merge Update dovecot for SIGKILL and dh.pem denials
Running dovecot on Debian 10 (buster) produced these denials: ``` type=AVC msg=audit(1601314853.031:9327): apparmor="DENIED" operation="signal" profile="dovecot" pid=21223 comm="dovecot" requested_mask="send" denied_mask="send" signal=kill peer="/usr/lib/dovecot/auth" type=AVC msg=audit(1601315453.655:9369): apparmor="DENIED" operation="signal" profile="dovecot" pid=21223 comm="dovecot" requested_mask="send" denied_mask="send" signal=kill peer="/usr/lib/dovecot/pop3" type=AVC msg=audit(1602939754.145:101362): apparmor="DENIED" operation="signal" profile="dovecot" pid=31632 comm="dovecot" requested_mask="send" denied_mask="send" signal=kill peer="/usr/lib/dovecot/pop3-login" ``` And: ``` type=AVC msg=audit(1603647096.369:24514): apparmor="DENIED" operation="open" profile="dovecot" name="/usr/share/dovecot/dh.pem" pid=28774 comm="doveconf" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 ``` These are fixed in respective comits. MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/671 Acked-by: John Johansen <john.johansen@canonical.com>
This commit is contained in:
@@ -33,8 +33,8 @@ profile dovecot /usr/{bin,sbin}/dovecot flags=(attach_disconnected) {
|
||||
capability sys_chroot,
|
||||
capability sys_resource,
|
||||
|
||||
signal send set=(int,quit,term) peer=/usr/lib/dovecot/*,
|
||||
signal send set=(int,quit,term) peer=dovecot-*,
|
||||
signal send set=(int,quit,term,kill) peer=/usr/lib/dovecot/*,
|
||||
signal send set=(int,quit,term,kill) peer=dovecot-*,
|
||||
|
||||
unix (receive, send) type=stream peer=(label=/usr/lib/dovecot/anvil),
|
||||
unix (receive, send) type=stream peer=(label=dovecot-anvil),
|
||||
@@ -67,6 +67,7 @@ profile dovecot /usr/{bin,sbin}/dovecot flags=(attach_disconnected) {
|
||||
/usr/lib/dovecot/ssl-params mrPx,
|
||||
/usr/lib/dovecot/stats Px,
|
||||
/usr/{bin,sbin}/dovecot mrix,
|
||||
/usr/share/dovecot/dh.pem r,
|
||||
/usr/share/dovecot/protocols.d/ r,
|
||||
/usr/share/dovecot/protocols.d/** r,
|
||||
/var/lib/dovecot/ w,
|
||||
|
Reference in New Issue
Block a user