sudoers: escape commas in lvs/lsblk -o arg lists (visudo -cf rejected the file)

Bare commas are command separators in sudoers; the lvs/lsblk -o option lists need
escaped commas. The file had never been visudo-validated live (the demo host ran the
agent root+direct). Surfaced by the BUNDLE host-install visudo -cf gate.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-28 08:56:16 +02:00
parent 29aeaa6bb4
commit a8d14fc384
2 changed files with 8 additions and 2 deletions
+2 -2
View File
@@ -24,7 +24,7 @@ Cmnd_Alias FELHOM_DISK = \
/usr/sbin/smartctl -a -j /dev/nvme[0-9]*n[0-9]*, \
/usr/sbin/smartctl -a -j /dev/vd[a-z]*, \
/usr/sbin/smartctl -a -j /dev/hd[a-z]*, \
/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- *
/usr/sbin/lvs --reportformat json --units b -o lv_name\,data_percent\,metadata_percent -- *
# Provisioning back-half (slice 8A, doc 03 §6): populate a guest's bootstrap config mount
# host-side (internal/provision). These are host-root ops the API token cannot do — a bind mount
@@ -43,7 +43,7 @@ Cmnd_Alias FELHOM_PROVISION = \
# only) + fstype before any exec — the wildcard is the coarse allowlist, the agent is the fine gate.
Cmnd_Alias FELHOM_FORMAT = \
/usr/sbin/blkid -p -o export /dev/*, \
/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/*, \
/usr/bin/lsblk -J -o NAME\,FSTYPE\,PTTYPE\,MOUNTPOINT /dev/*, \
/usr/sbin/mkfs.ext4 -F /dev/*, \
/usr/sbin/mkfs.xfs -f /dev/*