# Install as root:root 0440 and validate with visudo -cf. # The root-owned wrapper strictly validates the complete argument list. deploy ALL=(root) NOPASSWD: /usr/local/sbin/han-message-safety-mode