Skip to content

Discussion about the use of sudo and --use-remote-sudo with nixos-rebuild (switch) #381814

@Andrew15-5

Description

@Andrew15-5

This is closely related to #342338. Also see #342657.

Here we can discuss is sudo or --use-remote-sudo should be used with nixos-rebuild switch.

Context that triggered this issue:
https://matrix.to/#/#users:nixos.org
https://matrix.to/#/!RRerllqmbATpmbJgCn:nixos.org/$kiwUm4NtvAMvswl0Wg12Dm5upHprhzf86vHemMNrxQk
https://nixos.org/manual/nixos/stable/#sec-changing-config

TL;DR is that Emily isn't fully convinced that sudo should be avoided and --use-remote-sudo used instead. Another point that was mentioned is that the activation script probably has some stuff that does not require root and other stuff that does. So perhaps the "attack vector" can be further reduced by only using root for those stuff that actually require it. Though I'm not really aware of what polkit actually is, so I can't really comment on this one.

CC @emilazy @SigmaSquadron @Aleksanaa @cafkafk

Metadata

Metadata

Assignees

No one assigned

    Labels

    0.kind: questionRequests for a specific question to be answered6.topic: nixosIssues or PRs affecting NixOS modules, or package usability issues specific to NixOS
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions