浏览代码

“sudo” must remove SELinux restrictions

Otherwise, if “user” has the SELinux user “staff_u”, the user will
typically need to write “sudo -r unconfined_r -t unconfined_t”, which is
annoying.  If SELinux is disabled, these fields are ignored.
Demi Marie Obenour 3 年之前
父节点
当前提交
3bcc1c37ce
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      passwordless-root/qubes.sudoers

+ 1 - 1
passwordless-root/qubes.sudoers

@@ -1,4 +1,4 @@
-Defaults !requiretty
+Defaults role=unconfined_r, type=unconfined_t, !requiretty
 %qubes ALL=(ALL) NOPASSWD: ALL
 
 # WTF?! Have you lost your mind?!