Repository navigation
ubuntu: Add NOPASSWD sudoers rule for 25.10 and 26.04 - #1813
Conversation
There was a problem hiding this comment.
Code Review
This pull request configures passwordless sudo for the sudo group in Ubuntu 25.10 and 26.04 Containerfiles. The reviewer noted that files created in /etc/sudoers.d/ require strict permissions (such as 0440) to be recognized by sudo, and recommended explicitly setting these permissions to prevent the configuration from being ignored.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
debarshiray
left a comment
There was a problem hiding this comment.
Thanks for catching this, @NewtonChutney ! I didn't have the time to test this, but the changes and what you have written about them look sane to me. Maybe @Jmennius (our Ubuntu maintainer) will get to testing them before me.
Could you please correct your Git authorship information with your full name and a real email address? For what it's worth, projects as diverse as GCC, GnuPG, Linux, Moby and Podman don't allow anonymous or pseudonymous contributions.
|
I ran into this bug today also :) |
|
I think some PR descriptions are incorrect.
Directly contradicts the README of
It's either I, personally, prefer temporarily rolling back to the original sudo until the bug is fixed from |
|
Thanks @foriequal0. I'm not aware enough of sudo internals and this analysis was by Claude.. Maybe I should caveat it more clearly.. |
|
@Jmennius would you like to proceed with NOPASSWD or with a switch to the old sudo impl as suggested by @foriequal0:
|
|
Can we expedite merging this? |
|
I'll check on the weekend from my side. |
debarshiray
left a comment
There was a problem hiding this comment.
After digging into this in detail, I prefer to add NOPASSWD to sudoers(5) than to go back to the sudo.ws implementation.
Thanks to @foriequal0 this problem was reported to sudo-rs and fixed in version 0.2.15, and sticking to sudo-rs with NOPASSWD in sudoers(5) is a smaller deviation from the Ubuntu defaults. Hopefully, sudo-rs 0.2.15 will be available in future Ubuntu releases, and we won't need this workaround anymore.
Ubuntu 25.10 switched [1] from the sudo.ws [2] implementation of sudo(8) to sudo-rs [3]. A bug in the new implementation's use of the Pluggable Authentication Modules for Linux (or PAM) prevents it from working when invoked by a password-less user [4]. Work around this by adding a NOPASSWD tag to users in the 'sudo' group through a /etc/sudoers.d configuration snippet. The sudo.ws implementation in version 1.8.5 relaxed the requirement that /etc/sudoers and the snippets included from it must have 0440 as file permission [5], and the sudo-rs implementation behaves the same. Even then, the /etc/sudoers.d configuration snippet was set to 0440 for better hygiene. [1] https://trifectatech.org/blog/memory-safe-sudo-to-become-the-default-in-ubuntu/ https://discourse.ubuntu.com/t/adopting-sudo-rs-by-default-in-ubuntu-25-10 https://discourse.ubuntu.com/t/sudo-rs-is-now-default-for-questing-quokka [2] https://www.sudo.ws/ https://github.com/sudo-project/sudo [3] https://github.com/trifectatechfoundation/sudo-rs [4] sudo-rs commit 5debfcf1aa775201 trifectatechfoundation/sudo-rs@5debfcf1aa775201 trifectatechfoundation/sudo-rs#1657 trifectatechfoundation/sudo-rs#1656 [5] sudo-ws commit 415454ff59c1dab3 sudo-project/sudo@415454ff59c1dab3 https://github.com/sudo-project/sudo/blob/main/NEWS containers#1807
debarshiray
left a comment
There was a problem hiding this comment.
The Git commit message needs to be fixed. Currently, it says that "sudo-rs does not use PAM for authentication", which @foriequal0 pointed out is incorrect. It will be valuable to mention the references to the sudo-rs fix and issue, and the details around file permissions.
| RUN rm /extra-packages | ||
|
|
||
| # Allow passwordless sudo for the sudo group | ||
| RUN echo "%sudo ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/90-toolbx-nopasswd && \ |
There was a problem hiding this comment.
Strictly speaking, this comment is redundant because the code below it is self-explanatory and it repeats the Git commit message. If we want to have a comment, then it will be a lot more valuable to say that this is a workaround because it is obscure and unclear. :)
I took the liberty to make these changes. I am trying to make a new Toolbx 0.4 release and it will be good to have the most recent two Ubuntu images fixed as part of this. Unfortunately, we are running into one CI problem after another. So, merging this one reduces one lingering hurdle. |
Yepp, thanks! You should've taken co-authorship too! |
This is being addressed in #1847: |
|
The We have started seeing this recently elsewhere too. I am going to assume that it has nothing to do with this change and temporarily ignore it. |
No, I am already embarassed enough that I didn't find time for this for so long, when I was hoping to give @Jmennius a hand with the Ubuntu support. |
Ubuntu 25.10 switched from traditional C sudo to sudo-rs (Rust-based sudo).
Unlike C sudo, sudo-rs does not use PAM for authentication and therefore does not honor the nullok option in /etc/pam.d/common-auth.Edit: this analysis is wrong, check comment by foriequal0 below.
Toolbox creates users with an empty password (useradd --password "") and relies on PAM's nullok to accept blank authentication. With sudo-rs, this no longer works and the user gets prompted for a password.
Fix this by adding an explicit NOPASSWD sudoers drop-in for the sudo group, matching the approach already used in the Arch Containerfile. This works regardless of the sudo implementation.
Assisted by: Claude Opus 4.6 noreply@anthropic.com
Fixes #1807