Improve use of sudo for NFS export manipulation #3638
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Some users (myself and the denizens of #2642 included) want to allow Vagrant to manipulate NFS configs without requesting a sudo password each time.
The current approach, using "sudo -s" requires that we permit the whole shell to be run passwordless in sudoers, and that's rather too open to be safe.
This patch uses an alternative idiom, using 'tee' instead of output redirection to append to the exports file. On application of this patch, the following sudoers config (on OSX, at least), permits fully passwordless operation in a much safer manner:
This feels like a good interim step if work on the suid helper has paused for now.
NB: I've been unable to test the patch to the Linux plugin at this time.