Re: [OFFTOPIC] Re: [PATCH] Single user linux

From: Alan Cox (
Date: Tue Apr 24 2001 - 09:59:28 EST

> > Copying spool articles matching the peercred to the client does not
> Running procmail as the user who is to receive the email for local mail
> delivery as running it with gid mail (for eg) would allow one user to
> modify another's mail.

What is this gid mail crap ? You don't need priviledge. You get the mail by
asking the daemon for it. procmail needs no priviledge either if it is done

You just need to think about the security models in the right way. Linux gives
you the ability to do authenticated uid/gid checking over a socket connection.
That is an incredibly powerful model for real compartmentalisation.


