sudoers.in 2.12 KB
Newer Older
1 2
#
# Copyright (c) 2012 University of Utah and the Flux Group.
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
# 
# {{{EMULAB-LICENSE
# 
# This file is part of the Emulab network testbed software.
# 
# This file is free software: you can redistribute it and/or modify it
# under the terms of the GNU Affero General Public License as published by
# the Free Software Foundation, either version 3 of the License, or (at
# your option) any later version.
# 
# This file is distributed in the hope that it will be useful, but WITHOUT
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
# FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Affero General Public
# License for more details.
# 
# You should have received a copy of the GNU Affero General Public License
# along with this file.  If not, see <http://www.gnu.org/licenses/>.
# 
# }}}
22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63
#

#
# Emulab sudoers file. Serves double duty:
#
#  * Allows members of the wheel group to sudo without a password
#
#  * Replaces "suidperl" allowing any user to run a script in the
#    /usr/testbed/suidbin directory as root.
#
# For the latter, we clamp down on the environment of the user.
# suidperl just changed the effective uid to root and left all groups
# and the environment the same. We clean out the environment, including
# setting a default path.
#
# XXX we do not actually use this config right now since preserve_groups
# loses the primary group in the resulting group list. Emulab needs all
# the groups to be unchanged.
#

# setuid perl scripts
Cmnd_Alias	SPERL = @prefix@/suidbin/

Defaults	!env_reset
Defaults	!syslog, logfile="/var/log/sudo.log"

# attempt to preserve suidperl behavior
Defaults!SPERL	env_reset, stay_setuid, preserve_groups, !set_logname
# need the following if !env_reset
#Defaults!SPERL env_delete="IFS CDPATH ENV BASH_ENV", !set_home
# need the following if env_reset
Defaults!SPERL	secure_path="@prefix@/bin:@prefix@/sbin:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin"

# set to !logfile to turn off logging of sudo scripts
Defaults!SPERL	logfile="/var/log/sudo-scripts.log"

root		ALL = (ALL) ALL
%wheel		ALL = (ALL) NOPASSWD: ALL

# To implement suid perl scripts
ALL		ALL = (root) NOPASSWD: SPERL