mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-09-03 15:55:46 +00:00
Allow dovecot to use all signals
similar to commit 2f9d172c64
we discovered that there was a service outage
when dovecot tried to send a usr1 signal
type=AVC msg=audit(1648024138.249:184964): apparmor="DENIED" operation="signal" profile="dovecot" pid=1690 comm="dovecot" requested_mask="send" denied_mask="send" signal=usr1 peer="dovecot-imap-login"
This commit is contained in:
@@ -33,8 +33,8 @@ profile dovecot /usr/{bin,sbin}/dovecot flags=(attach_disconnected) {
|
|||||||
capability sys_chroot,
|
capability sys_chroot,
|
||||||
capability sys_resource,
|
capability sys_resource,
|
||||||
|
|
||||||
signal send set=(int,quit,term,kill) peer=/usr/lib/dovecot/*,
|
signal send peer=/usr/lib/dovecot/*,
|
||||||
signal send set=(int,quit,term,kill) peer=dovecot-*,
|
signal send peer=dovecot-*,
|
||||||
|
|
||||||
unix (receive, send) type=stream peer=(label=/usr/lib/dovecot/anvil),
|
unix (receive, send) type=stream peer=(label=/usr/lib/dovecot/anvil),
|
||||||
unix (receive, send) type=stream peer=(label=dovecot-anvil),
|
unix (receive, send) type=stream peer=(label=dovecot-anvil),
|
||||||
|
Reference in New Issue
Block a user