Wener Notes

doas

约 1 分钟阅读
  • doasGitHub Fileopenbsd/src/usr.bin/doas95% of the features of sudo with a fraction of the codebase · 约 1000 loc - sudo 约 18k loc · /etc/doas.conf · doas.1 · doas.conf.5笔记:doas
    • 95% of the features of sudo with a fraction of the codebase
    • 约 1000 loc - sudo 约 18k loc
  • /etc/doas.conf
  • doas.1Linkman.openbsd.org/doas95% of the features of sudo with a fraction of the codebase · 约 1000 loc - sudo 约 18k loc · /etc/doas.conf · doas.1 · doas.conf.5笔记:doas
  • doas.conf.5Linkman.openbsd.org/doas.conf.595% of the features of sudo with a fraction of the codebase · 约 1000 loc - sudo 约 18k loc · /etc/doas.conf · doas.1 · doas.conf.5笔记:doas
bash
# run as wener
doas -u wener whoami
# -s shell -> sudo su
doas -s
optionmean
-a styleauth style in /etc/login.conf
-C configcheck dose.conf
-Lclear persisted auth
-nnon interactive mode - 要求 nopass
-sexec $SHELL or shell in /etc/passwd
-u useras user - 默认 root

doas.conf

配置语法
permit|deny [options] identity [as target] [cmd command [args ...]]
  • permit|deny
  • options
    • nopass - 不需要输入密码
    • nolog - 不记录成功执行的命令到 syslogd
    • persist - 记录密码授权一段时间 - 类似 macOS 体验
    • keepenv - 保留环境变量
      • 默认环境变量 HOME, LOGNAME, PATH, SHELL, USER, DOAS_USER, DISPLAY TERM
    • setenv { [variable ...] [variable=value ...] } - 设置环境变量
      • 前缀 - 可移除
      • 值可用 $ 引用别的环境变量
  • identity - 用户名、分组 :group、ID
  • as target
  • cmd command - 限定执行命令
  • args [argument ...] - 限定参数
doas.conf
permit nopass admin as root

permit nopass wener as root cmd apk args upgrade

permit nopass setenv { -http_proxy APT_CONFIG=/etc/apt/apt.conf.d/50appstream } :updaters cmd apt args update

# group :wheel
permit nopass keepenv :wheel

关联信息

反向链接、本文链接的其他页面和外部资料。

反向链接

  • AlpineLinux 版本历史
    笔记 · doas

    发布频率 · 每年两个版本 - 5 月左右一个,11 月左右一个 · 每年年底的 Linux 版本一般为 LTS - 因此下半年版本一般也会更新内核版本 · 每个版本的支持周期约为两年 - 也就是共计 4 个活跃支持版本 · main 仓库支持两年 - 发布后以稳定为主,基本不升级

References

GitHub1 条
其他外链2 条
最近更新commit f0320f1Edit

On this page