Files
my-vault/03_Resources/Development/Linux/sudo-command-blocking.md
T
windyboy b182762e14 refactor(vault): Phase 3 — metadata convergence
- Backfill `created` frontmatter on 266 active notes (git date or mtime)
- Normalize `status` to 4 values: draft/active/done/archived (11 notes)
  - Active/进行中/needs-review → active
  - archive → archived
  - 待执行/conditional → draft
  - 完成/accepted → done
- Declare clipper boundary: 04_Archive/Inbox-Clippings/** exempt from migration
- Update depth rule: max 3 → max 4 levels (new notes only)
- Add metadata-converge.mjs script for reproducibility
2026-09-26 11:37:19 +08:00

27 lines
1.2 KiB
Markdown

---
created: 2026-01-05
---
If your user is called `user` and your host is called you could add these lines to `/etc/sudoers`:
```
user = (root) NOPASSWD: /sbin/shutdown
user = (root) NOPASSWD: /sbin/reboot
```
This will allow the user `user` to run the desired commands without entering a password. All other sudoed commands will still require a password.
The commands specified in the `sudoers` file _must_ be fully qualified (i.e. using the absolute path to the command to run)
If the command ends with a trailing `/` character and points to a directory, the user will be able to run any command in that directory (but not in any sub-directories therein). In the following example, the user `user` can run any command in the directory `/home/someuser/bin/`:
```
user = (root) NOPASSWD: /home/someuser/bin/
```
As an alternative to editing the `/etc/sudoers` file, you could add the two lines to a new file in `/etc/sudoers.d` e.g. `/etc/sudoers.d/shutdown`. This is an elegant way of separating different changes to the `sudo` rights and also leaves the original `sudoers` file untouched for easier upgrades.
*visudo can be used to edit those files too, this prevent error that could lock you out of the system*
```
sudo visudo -f /etc/sudoers.d/shutdown
```