Oeps... seems this is indeed wrongly done. I got the same errors in my log:
Unfortunately I don't have an older server running older Dovecot to see what permissions were before.
However, how do you know lmtp is running as mail?
In my case it's running as user or as root.
root 69857 0.0...