Skip to content

ubuntu: Add NOPASSWD sudoers rule for 25.10 and 26.04 - #1813

Merged
debarshiray merged 1 commit into
containers:mainfrom
NewtonChutney:main
Oct 9, 2026
Merged

debarshiray merged 1 commit into
containers:mainfrom
NewtonChutney:main

Conversation

@NewtonChutney

@NewtonChutney NewtonChutney commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Ubuntu 25.10 switched from traditional C sudo to sudo-rs (Rust-based sudo). Unlike C sudo, sudo-rs does not use PAM for authentication and therefore does not honor the nullok option in /etc/pam.d/common-auth.
Edit: this analysis is wrong, check comment by foriequal0 below.

Toolbox creates users with an empty password (useradd --password "") and relies on PAM's nullok to accept blank authentication. With sudo-rs, this no longer works and the user gets prompted for a password.

Fix this by adding an explicit NOPASSWD sudoers drop-in for the sudo group, matching the approach already used in the Arch Containerfile. This works regardless of the sudo implementation.

Assisted by: Claude Opus 4.6 noreply@anthropic.com

Fixes #1807

@NewtonChutney
NewtonChutney requested a review from Jmennius as a code owner July 2, 2026 08:05

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request configures passwordless sudo for the sudo group in Ubuntu 25.10 and 26.04 Containerfiles. The reviewer noted that files created in /etc/sudoers.d/ require strict permissions (such as 0440) to be recognized by sudo, and recommended explicitly setting these permissions to prevent the configuration from being ignored.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread images/ubuntu/25.10/Containerfile Outdated
Comment thread images/ubuntu/26.04/Containerfile Outdated

@debarshiray debarshiray left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for catching this, @NewtonChutney ! I didn't have the time to test this, but the changes and what you have written about them look sane to me. Maybe @Jmennius (our Ubuntu maintainer) will get to testing them before me.

Could you please correct your Git authorship information with your full name and a real email address? For what it's worth, projects as diverse as GCC, GnuPG, Linux, Moby and Podman don't allow anonymous or pseudonymous contributions.

@peer-cat

Copy link
Copy Markdown

I ran into this bug today also :)

@foriequal0

Copy link
Copy Markdown

I think some PR descriptions are incorrect.

sudo-rs does not use PAM for authentication

Directly contradicts the README of sudo-rs:

Sudo-rs always uses PAM for authentication
https://github.com/trifectatechfoundation/sudo-rs/blob/86b4f09c9af23413beb643aff515f2ef1901fdb7/README.md?plain=1#L284-L285

It's either sudo-rs's intended policy or just their bug. I created an issue in their repo: trifectatechfoundation/sudo-rs#1656

I, personally, prefer temporarily rolling back to the original sudo until the bug is fixed from sudo-rs

update-alternatives --set sudo /usr/bin/sudo.ws

@NewtonChutney

Copy link
Copy Markdown
Contributor Author

Thanks @foriequal0. I'm not aware enough of sudo internals and this analysis was by Claude.. Maybe I should caveat it more clearly..
I had only tested that this PR fixed the issue on both images, and assumed Clsude's analysis was correct.. 🫠

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed.
https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/local/buildset/51b2fb8b41754f6cb850579e715b62ee

✔️ unit-test SUCCESS in 2m 28s
✔️ unit-test-migration-path-for-coreos-toolbox SUCCESS in 3m 14s
✔️ unit-test-restricted SUCCESS in 2m 26s
✔️ system-test-fedora-rawhide-commands-options SUCCESS in 47m 42s
✔️ system-test-fedora-rawhide-runtime-environment-arch-fedora SUCCESS in 36m 25s
✔️ system-test-fedora-rawhide-runtime-environment-ubuntu SUCCESS in 8m 22s
✔️ system-test-fedora-44-commands-options SUCCESS in 37m 39s
✔️ system-test-fedora-44-runtime-environment-arch-fedora SUCCESS in 28m 38s
✔️ system-test-fedora-44-runtime-environment-ubuntu SUCCESS in 8m 06s
✔️ system-test-fedora-43-commands-options SUCCESS in 42m 32s
✔️ system-test-fedora-43-runtime-environment-arch-fedora SUCCESS in 32m 29s
✔️ system-test-fedora-43-runtime-environment-ubuntu SUCCESS in 7m 36s
✔️ system-test-fedora-42-commands-options SUCCESS in 36m 50s
✔️ system-test-fedora-42-runtime-environment-arch-fedora SUCCESS in 28m 25s
✔️ system-test-fedora-42-runtime-environment-ubuntu SUCCESS in 7m 07s
❌ system-test-fedora-coreos-next-commands-options NODE_FAILURE Node(set) request 200-0000179715 failed in 0s
❌ system-test-fedora-coreos-next-runtime-environment-arch-fedora NODE_FAILURE Node(set) request 200-0000179716 failed in 0s
❌ system-test-fedora-coreos-next-runtime-environment-ubuntu NODE_FAILURE Node(set) request 200-0000179717 failed in 0s
✔️ system-test-fedora-coreos-stable-commands-options SUCCESS in 37m 56s
✔️ system-test-fedora-coreos-stable-runtime-environment-arch-fedora SUCCESS in 29m 56s
✔️ system-test-fedora-coreos-stable-runtime-environment-ubuntu SUCCESS in 9m 34s
❌ system-test-fedora-coreos-testing-commands-options NODE_FAILURE Node(set) request 200-0000179721 failed in 0s
❌ system-test-fedora-coreos-testing-runtime-environment-arch-fedora NODE_FAILURE Node(set) request 200-0000179722 failed in 0s
❌ system-test-fedora-coreos-testing-runtime-environment-ubuntu NODE_FAILURE Node(set) request 200-0000179723 failed in 0s

@NewtonChutney

Copy link
Copy Markdown
Contributor Author

@Jmennius would you like to proceed with NOPASSWD or with a switch to the old sudo impl as suggested by @foriequal0:

I, personally, prefer temporarily rolling back to the original sudo until the bug is fixed from sudo-rs

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed.
https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/local/buildset/64c9e0dc433d48b99674c6d9110211d7

✔️ unit-test SUCCESS in 2m 22s
✔️ unit-test-migration-path-for-coreos-toolbox SUCCESS in 3m 22s
✔️ unit-test-restricted SUCCESS in 2m 11s
✔️ system-test-fedora-rawhide-commands-options SUCCESS in 39m 35s
✔️ system-test-fedora-rawhide-runtime-environment-arch-fedora SUCCESS in 27m 44s
✔️ system-test-fedora-rawhide-runtime-environment-ubuntu SUCCESS in 7m 41s
✔️ system-test-fedora-44-commands-options SUCCESS in 40m 48s
✔️ system-test-fedora-44-runtime-environment-arch-fedora SUCCESS in 30m 56s
✔️ system-test-fedora-44-runtime-environment-ubuntu SUCCESS in 7m 56s
✔️ system-test-fedora-43-commands-options SUCCESS in 38m 45s
✔️ system-test-fedora-43-runtime-environment-arch-fedora SUCCESS in 30m 16s
✔️ system-test-fedora-43-runtime-environment-ubuntu SUCCESS in 7m 47s
✔️ system-test-fedora-42-commands-options SUCCESS in 34m 40s
✔️ system-test-fedora-42-runtime-environment-arch-fedora SUCCESS in 26m 15s
✔️ system-test-fedora-42-runtime-environment-ubuntu SUCCESS in 7m 21s
❌ system-test-fedora-coreos-next-commands-options RETRY_LIMIT in 26s
❌ system-test-fedora-coreos-next-runtime-environment-arch-fedora RETRY_LIMIT in 26s
❌ system-test-fedora-coreos-next-runtime-environment-ubuntu RETRY_LIMIT in 26s
✔️ system-test-fedora-coreos-stable-commands-options SUCCESS in 41m 16s
✔️ system-test-fedora-coreos-stable-runtime-environment-arch-fedora SUCCESS in 32m 50s
✔️ system-test-fedora-coreos-stable-runtime-environment-ubuntu SUCCESS in 9m 17s
✔️ system-test-fedora-coreos-testing-commands-options SUCCESS in 42m 21s
✔️ system-test-fedora-coreos-testing-runtime-environment-arch-fedora SUCCESS in 34m 03s
✔️ system-test-fedora-coreos-testing-runtime-environment-ubuntu SUCCESS in 9m 43s

@NewtonChutney

Copy link
Copy Markdown
Contributor Author

Can we expedite merging this?
I feel it's a big usability bug for users.. 🥲

@Jmennius

Jmennius commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

I'll check on the weekend from my side.

@debarshiray debarshiray left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After digging into this in detail, I prefer to add NOPASSWD to sudoers(5) than to go back to the sudo.ws implementation.

Thanks to @foriequal0 this problem was reported to sudo-rs and fixed in version 0.2.15, and sticking to sudo-rs with NOPASSWD in sudoers(5) is a smaller deviation from the Ubuntu defaults. Hopefully, sudo-rs 0.2.15 will be available in future Ubuntu releases, and we won't need this workaround anymore.

Ubuntu 25.10 switched [1] from the sudo.ws [2] implementation of sudo(8)
to sudo-rs [3].  A bug in the new implementation's use of the Pluggable
Authentication Modules for Linux (or PAM) prevents it from working when
invoked by a password-less user [4].

Work around this by adding a NOPASSWD tag to users in the 'sudo' group
through a /etc/sudoers.d configuration snippet.

The sudo.ws implementation in version 1.8.5 relaxed the requirement that
/etc/sudoers and the snippets included from it must have 0440 as file
permission [5], and the sudo-rs implementation behaves the same.  Even
then, the /etc/sudoers.d configuration snippet was set to 0440 for
better hygiene.

[1] https://trifectatech.org/blog/memory-safe-sudo-to-become-the-default-in-ubuntu/
    https://discourse.ubuntu.com/t/adopting-sudo-rs-by-default-in-ubuntu-25-10
    https://discourse.ubuntu.com/t/sudo-rs-is-now-default-for-questing-quokka

[2] https://www.sudo.ws/
    https://github.com/sudo-project/sudo

[3] https://github.com/trifectatechfoundation/sudo-rs

[4] sudo-rs commit 5debfcf1aa775201
    trifectatechfoundation/sudo-rs@5debfcf1aa775201
    trifectatechfoundation/sudo-rs#1657
    trifectatechfoundation/sudo-rs#1656

[5] sudo-ws commit 415454ff59c1dab3
    sudo-project/sudo@415454ff59c1dab3
    https://github.com/sudo-project/sudo/blob/main/NEWS

containers#1807

@debarshiray debarshiray left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Git commit message needs to be fixed. Currently, it says that "sudo-rs does not use PAM for authentication", which @foriequal0 pointed out is incorrect. It will be valuable to mention the references to the sudo-rs fix and issue, and the details around file permissions.

RUN rm /extra-packages

# Allow passwordless sudo for the sudo group
RUN echo "%sudo ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/90-toolbx-nopasswd && \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Strictly speaking, this comment is redundant because the code below it is self-explanatory and it repeats the Git commit message. If we want to have a comment, then it will be a lot more valuable to say that this is a workaround because it is obscure and unclear. :)

@debarshiray

Copy link
Copy Markdown
Member

The Git commit message needs to be fixed. Currently, it says that "sudo-rs does not use PAM for authentication", which @foriequal0 pointed out is incorrect. It will be valuable to mention the references to the sudo-rs fix and issue, and the details around file permissions.

[...]

Strictly speaking, this comment is redundant because the code below it is self-explanatory and it repeats the Git commit message. If we want to have a comment, then it will be a lot more valuable to say that this is a workaround because it is obscure and unclear. :)

I took the liberty to make these changes.

I am trying to make a new Toolbx 0.4 release and it will be good to have the most recent two Ubuntu images fixed as part of this. Unfortunately, we are running into one CI problem after another. So, merging this one reduces one lingering hurdle.

@NewtonChutney

Copy link
Copy Markdown
Contributor Author

I took the liberty to make these changes.

Yepp, thanks! You should've taken co-authorship too!

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed.
https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/local/buildset/3170fc64397d4a5f9356055020c5d412

✔️ unit-test SUCCESS in 2m 13s
✔️ unit-test-migration-path-for-coreos-toolbox SUCCESS in 3m 13s
✔️ unit-test-restricted SUCCESS in 2m 14s
✔️ system-test-fedora-rawhide-commands-options SUCCESS in 36m 15s
✔️ system-test-fedora-rawhide-runtime-environment-arch-fedora SUCCESS in 25m 36s
✔️ system-test-fedora-rawhide-runtime-environment-ubuntu SUCCESS in 6m 20s
✔️ system-test-fedora-44-commands-options SUCCESS in 33m 07s
✔️ system-test-fedora-44-runtime-environment-arch-fedora SUCCESS in 24m 47s
✔️ system-test-fedora-44-runtime-environment-ubuntu SUCCESS in 6m 24s
✔️ system-test-fedora-43-commands-options SUCCESS in 32m 49s
✔️ system-test-fedora-43-runtime-environment-arch-fedora SUCCESS in 37m 51s
✔️ system-test-fedora-43-runtime-environment-ubuntu SUCCESS in 6m 03s
✔️ system-test-fedora-42-commands-options SUCCESS in 50m 31s
✔️ system-test-fedora-42-runtime-environment-arch-fedora SUCCESS in 37m 16s
✔️ system-test-fedora-42-runtime-environment-ubuntu SUCCESS in 10m 28s
❌ system-test-fedora-coreos-next-commands-options RETRY_LIMIT in 1m 09s
❌ system-test-fedora-coreos-next-runtime-environment-arch-fedora RETRY_LIMIT in 1m 05s
❌ system-test-fedora-coreos-next-runtime-environment-ubuntu RETRY_LIMIT in 1m 02s
✔️ system-test-fedora-coreos-stable-commands-options SUCCESS in 54m 17s
✔️ system-test-fedora-coreos-stable-runtime-environment-arch-fedora SUCCESS in 44m 35s
✔️ system-test-fedora-coreos-stable-runtime-environment-ubuntu SUCCESS in 10m 33s
✔️ system-test-fedora-coreos-testing-commands-options SUCCESS in 54m 50s
✔️ system-test-fedora-coreos-testing-runtime-environment-arch-fedora SUCCESS in 44m 56s
✔️ system-test-fedora-coreos-testing-runtime-environment-ubuntu SUCCESS in 8m 05s

@debarshiray

Copy link
Copy Markdown
Member

Build failed. https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/local/buildset/3170fc64397d4a5f9356055020c5d412

[...]

❌ system-test-fedora-coreos-next-commands-options RETRY_LIMIT in 1m 09s
❌ system-test-fedora-coreos-next-runtime-environment-arch-fedora RETRY_LIMIT in 1m 05s
❌ system-test-fedora-coreos-next-runtime-environment-ubuntu RETRY_LIMIT in 1m 02s

This is being addressed in #1847:

TASK [Install RPM packages]
fedora-coreos-next | Inactive requests:
fedora-coreos-next |   udisks2 (already provided by udisks2-2.11.2-1.fc45.x86_64)
fedora-coreos-next |   rsync (already provided by rsync-3.5.0-2.fc45.x86_64)
fedora-coreos-next | Checking out tree e6685e0...done
fedora-coreos-next | Enabled rpm-md repositories: fedora-cisco-openh264 updates-testing updates fedora updates-archive
fedora-coreos-next | Importing rpm-md...done
fedora-coreos-next | rpm-md repo 'fedora-cisco-openh264' (cached); generated: 2026-03-24T10:56:00Z solvables: 3
fedora-coreos-next | rpm-md repo 'updates-testing' (cached); generated: 2026-10-09T02:01:04Z solvables: 13390
fedora-coreos-next | rpm-md repo 'updates' (cached); generated: 2018-02-20T19:18:14Z solvables: 0
fedora-coreos-next | rpm-md repo 'fedora' (cached); generated: 2026-10-09T08:30:58Z solvables: 75855
fedora-coreos-next | rpm-md repo 'updates-archive' (cached); generated: 2026-08-21T13:38:41Z solvables: 0
fedora-coreos-next | Resolving dependencies...done
fedora-coreos-next | error: Could not depsolve transaction; 1 problem detected:
fedora-coreos-next |  Problem: libgcc-16.2.1-2.fc45.1.i686 from fedora does not belong to a distupgrade repository
fedora-coreos-next |   - package gcc-16.2.1-2.fc45.1.x86_64 from fedora requires libgcc >= 16.2.1-2.fc45.1, but none of the providers can be installed
fedora-coreos-next |   - cannot install both libgcc-16.2.1-2.fc45.1.x86_64 from fedora and libgcc-16.2.1-2.fc45.x86_64 from @System
fedora-coreos-next |   - conflicting requests

@debarshiray

Copy link
Copy Markdown
Member

The ubuntu-tests job is failing with:

not ok 184 network: DNS inside Arch Linux in 591ms
# tags: arch-fedora runtime-environment
# (from function `assert_line' in file test/system/libs/bats-assert/src/assert.bash, line 488,
#  in test file test/system/203-network.bats, line 283)
#   `assert_line --index 0 "$ipv4_addr"' failed
#
# -- line differs --
# index    : 0
# expected : 193.0.14.129
# actual   :
# --
#

We have started seeing this recently elsewhere too. I am going to assume that it has nothing to do with this change and temporarily ignore it.

@debarshiray
debarshiray merged commit c4dd605 into containers:main Oct 9, 2026
8 of 10 checks passed
@debarshiray

Copy link
Copy Markdown
Member

I took the liberty to make these changes.

Yepp, thanks! You should've taken co-authorship too!

No, I am already embarassed enough that I didn't find time for this for so long, when I was hoping to give @Jmennius a hand with the Ubuntu support.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sudo(8) doesn't work in ubuntu-toolbox:25.10 and 26.04

5 participants