postfix: allow postfix pipe to watch mail spool
type=AVC msg=audit(1719451104.395:18364): avc: denied { watch } for pid=288883 comm="deliver" path="/var/spool/mail/domains/concord.sh/me@concord.sh/mail/dovecot-uidlist.lock" dev="dm-0" ino=17638966 scontext=system_u:system_r:postfix_pipe_t:s0 tcontext=system_u:object_r:mail_spool_t:s0 tclass=file permissive=0 Signed-off-by: Kenton Groombridge <concord@gentoo.org>
This commit is contained in:
parent
06a80c3d8a
commit
bfcaec9bab
@ -615,6 +615,7 @@ optional_policy(`
|
||||
|
||||
optional_policy(`
|
||||
mta_manage_spool(postfix_pipe_t)
|
||||
mta_watch_spool(postfix_pipe_t)
|
||||
mta_send_mail(postfix_pipe_t)
|
||||
')
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user