severity 676676 serious
thanks

I'm using dovecot-pop3d on a server which has just been upgraded from
squeeze to wheezy, and found this bug as well. I confirm that without

 mail_privileged_group = mail

mail is not removed from inbox.

I'm marking this bug as RC because 

a) it should be easy to fix, and
b) I really believe we should not release wheezy with this bug.


According to dovecot documentation:

  /var/mail/ dotlocks

  Often mbox write locks include dotlock, which means that Dovecot
  needs to create a new "<mbox>.lock" file to the directory where the
  mbox file exists. If your INBOXes are in /var/mail/ directory you
  may have to give Dovecot write access to the directory. There are
  two ways the /var/mail/ directory's permissions have traditionally
  been set up:

* World-writable with sticky bit set, allowing anyone to create new
  files but not overwrite or delete existing files owned by someone
  else (ie. same as /tmp). You can do this with chmod a+rwxt /var/mail

* Directory owned by a mail group and the directory set to
  group-writable

  You can give Dovecot access to mail group by setting:

  mail_privileged_group = mail

Debian policy clearly follows the second model so dovecot should be
configured accordingly by default.


Thanks.


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to