docker-mailserver/target/scripts/startup
Georg Lauterbach 26214491ef
fix: Drop special bits from Postfix maildrop/ and public/ directory permissions (#3625)
* update K8s deployment

Because `allowPrivilegeEscalation` controls SUID/SGID, we require it
when postdrop is invoked.

* correct permissions for maildrop/public

The reason our permissions previously worked out as that in setups where
SUID/SGID worked, the binaries used to place files in these directories
already have SGID set; the current set of permissions makes less sense
(as explained in this comment:
https://github.com/docker-mailserver/docker-mailserver/issues/3619#issuecomment-1793816412)

Since the binaries used to place files inside these directories alredy
have SUID/SGID set, we do not require these bits (or the sticky bit) to
be set on the directories.

* Apply suggestions from code review

---------

Co-authored-by: Brennan Kinney <5098581+polarathene@users.noreply.github.com>
2023-11-10 19:57:17 +01:00
..
setup.d fix: Drop special bits from Postfix maildrop/ and public/ directory permissions (#3625) 2023-11-10 19:57:17 +01:00
check-stack.sh Change 'for' style (#3368) 2023-05-26 14:00:40 +02:00
daemons-stack.sh Change 'for' style (#3368) 2023-05-26 14:00:40 +02:00
setup-stack.sh Change 'for' style (#3368) 2023-05-26 14:00:40 +02:00
variables-stack.sh feat: Allow changing the Dovecot vmail UID/GID via ENV (#3550) 2023-10-01 00:20:03 +13:00