File dovecot24-part2.diff of Package apparmor
diff --git a/profiles/apparmor.d/abstractions/dovecot-common b/profiles/apparmor.d/abstractions/dovecot-common
index d39159ecf..facbdfd25 100644
--- a/profiles/apparmor.d/abstractions/dovecot-common
+++ b/profiles/apparmor.d/abstractions/dovecot-common
@@ -20,6 +20,7 @@
owner @{run}/dovecot/config rw,
owner @{run}/dovecot/dovecot.conf.binary r,
+ owner @{run}/dovecot/dovecot.conf.binary.* r,
owner /tmp/doveconf.* r,
# Include additions to the abstraction
diff --git a/profiles/apparmor.d/usr.lib.dovecot.config b/profiles/apparmor.d/usr.lib.dovecot.config
index 471e0651d..24d1f0752 100644
--- a/profiles/apparmor.d/usr.lib.dovecot.config
+++ b/profiles/apparmor.d/usr.lib.dovecot.config
@@ -21,6 +21,7 @@ profile dovecot-config /usr/lib*/dovecot/config {
capability dac_read_search,
capability dac_override,
+ capability setuid,
/etc/dovecot/** r,
/usr/bin/doveconf rix,
diff --git a/profiles/apparmor.d/usr.lib.dovecot.imap-login b/profiles/apparmor.d/usr.lib.dovecot.imap-login
index a7481d698..c43b4ad54 100644
--- a/profiles/apparmor.d/usr.lib.dovecot.imap-login
+++ b/profiles/apparmor.d/usr.lib.dovecot.imap-login
@@ -18,6 +18,7 @@ profile dovecot-imap-login /usr/lib*/dovecot/imap-login {
include <abstractions/base>
include <abstractions/dovecot-common>
+ capability dac_override,
capability setuid,
capability sys_chroot,