> but do we really actually need the .so's in /var?
Linux Filesystem Standard v3.0 does not allow executable code under /var directory. Postfix is in non-compliance. And this will become more problematic as containerization and virtualization comes into play. Citation: https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch05s02.html