On Thu, Sep 24, 2026 at 5:24 PM Wietse Venema via Postfix-users <[email protected]> wrote: > > Jaroslaw Rafa via Postfix-users: > > Dnia 24.09.2026 o godz. 08:03:30 Wietse Venema via Postfix-users pisze: > > > Wietse Venema via Postfix-users: > > > > In a "No new privs" world, the set-gid feature becomes unavailable, > > > > and must be replaced with authenticated IPC (inter-process > > > > communication). This may be facilitated with systemd-managed sockets > > > > that launch client programs with suitable privileges. > > > > > > How would that work with Postfix in a container? This solution would > > > make systemd a hard dependency, breaking configurations where Postfix > > > currently runs as PID=1. > > > > The goal of a containerized solution is to isolate the service that's > > running in a container from anything else, so I think using "No new privs" > > feature in a container has no sense. Should it protect the service from > > itself? This should be turned off in a container. > > Is "No new privs" a global kernel setting, or is it subject to name > space boundaries?
If set for one process, it's for this process and all childs. So if you set it for PID1, it's global. Once set for a process you cannot remove it anymore. Thorsten > Linux-specific knowledge is strictly on a need-to-know basis. > > Wietse > _______________________________________________ > Postfix-users mailing list -- [email protected] > To unsubscribe send an email to [email protected] -- Thorsten Kukuk, Distinguished Engineer, Future Technologies SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461 Nuernberg, Germany Geschäftsführer: Stefan Gaiser, Jochen Jaser, Abhinav Puri (HRB 36809, AG Nürnberg) _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
