New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
nixos/sudo: default rule should be first #87579
Conversation
@GrahamcOfBorg test sudo |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good. Handling sudo rules is tricky, this achieves the expected behavior.
Could something be added to the test for this, say by setting |
If somebody more familiar with Sorry it took me so long to get back to this (and even sorrier that it was just to say "I can't do that"). |
In /etc/sudoers, the last-matched rule will override all previously-matched rules. Thus, make the default rule show up first (but still allow some wiggle room for a user to `mkBefore` it), before any user-defined rules.
In /etc/sudoers, the last-matched rule will override all
previously-matched rules. Thus, make the default rule show up first (but
still allow some wiggle room for a user to
mkBefore
it), before anyuser-defined rules.
Motivation for this change
Addresses #87555. I'll backport this to 20.03 after this gets merged (or whoever merges this can take care of that for me; I don't mind either way, but that might be easier than waiting for me to follow up).
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)