mailbox_command = procmail -a "$EXTENSION"

and not with the normal enabled command:

mailbox_command = /usr/bin/procmail-wrapper -o -a $DOMAIN -d $LOGNAME

Which is Postfix just using the raw procmail command instead of procmail-wrapper
though? Presumably procmail-wrapper is specified in main.cf.

yes, Postfix is using the command '
mailbox_command = procmail -a "$EXTENSION"', when the permission are not correct.
If it is a mail generated by root, postfix uses the special procmail-wrapper command.
That is really confusing .. where is this different command specified in the Postfix config file?

