AppArmor profile exchange
# $Id: usr.lib.postfix.master 90 2006-08-04 19:13:59Z seth_arnold $
# ------------------------------------------------------------------
#
# Copyright (C) 2002-2006 Novell/SUSE
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of version 2 of the GNU General Public
# License published by the Free Software Foundation.
#
# ------------------------------------------------------------------
#include <tunables/global>
/usr/lib/postfix/master {
#include <abstractions/base>
#include <abstractions/kerberosclient>
#include <abstractions/nameservice>
#include <program-chunks/postfix-common>
capability dac_override,
capability kill,
capability net_bind_service,
capability sys_ptrace,
/etc/postfix/master.cf r,
owner /proc/sys/kernel/ngroups_max r,
owner /usr/lib/** m,
/usr/lib/** rPx,
/usr/lib/postfix/master mrix,
owner /var/lib/postfix/master.lock rwk,
owner /var/run/nscd/services r,
owner /var/spool/postfix/active/ r,
owner /var/spool/postfix/deferred/ r,
owner /var/spool/postfix/incoming/ r,
owner /var/spool/postfix/maildrop/ r,
owner /{var/spool/postfix/,}pid/master.pid k,
/{var/spool/postfix/,}pid/master.pid rw,
/{var/spool/postfix/,}private/* wl,
/{var/spool/postfix/,}private/tlsmgr rwl,
/{var/spool/postfix/,}public/{cleanup,flush,pickup,qmgr,showq,tlsmgr} rwl,
}