On Thu, Sep 24, 2026 at 5:24 PM Wietse Venema via Postfix-users
<[email protected]> wrote:
>
> Jaroslaw Rafa via Postfix-users:
> > Dnia 24.09.2026 o godz. 08:03:30 Wietse Venema via Postfix-users pisze:
> > > Wietse Venema via Postfix-users:
> > > > In a "No new privs" world, the set-gid feature becomes unavailable,
> > > > and must be replaced with authenticated IPC (inter-process
> > > > communication). This may be facilitated with systemd-managed sockets
> > > > that launch client programs with suitable privileges.
> > >
> > > How would that work with Postfix in a container? This solution would
> > > make systemd a hard dependency, breaking configurations where Postfix
> > > currently runs as PID=1.
> >
> > The goal of a containerized solution is to isolate the service that's
> > running in a container from anything else, so I think using "No new privs"
> > feature in a container has no sense. Should it protect the service from
> > itself? This should be turned off in a container.
>
> Is "No new privs" a global kernel setting, or is it subject to name
> space boundaries?

If set for one process, it's for this process and all childs.
So if you set it for PID1, it's global. Once set for a process you
cannot remove it anymore.

Thorsten

>  Linux-specific knowledge is strictly on a need-to-know basis.
>
>         Wietse
> _______________________________________________
> Postfix-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]



-- 
Thorsten Kukuk, Distinguished Engineer, Future Technologies
SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461
Nuernberg, Germany
Geschäftsführer: Stefan Gaiser, Jochen Jaser, Abhinav Puri (HRB 36809,
AG Nürnberg)
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to