Without this restriction system users can start processes with root privileges: $ sudo -u mail systemd-run --pipe -q id uid=0(root) gid=0(root) groups=0(root) |
||
|---|---|---|
| .. | ||
| Makefile | ||
| pam-configs_su.qubes | ||
| pam.d_su.qubes | ||
| polkit-1-qubes-allow-all.pkla | ||
| polkit-1-qubes-allow-all.rules | ||
| qubes.sudoers | ||