Unfortunately, this is about as easy as it gets. Practically though, it isn’t going to matter. It sounds like run0
will be a drop-in replacement for sudo
. We will know for sure in about 3 days (at the rate at which they assimilate features).
It gets rid of one more SUID binary. That’s always a win for security.
Sudo probably is way more comfortable to use and has way more configurable, too – that usually does not help to make a tool secure either:-)
While it may be true that getting rid of SUID binary is ideal, widening systemd’s security surface area is much more concerning to me than the sudo binary.