Bug 16321

Summary: Enabling `pam-wheel` does not allow add wheel to sudoers
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Nate Kent <yocto>
Component: oe-core otherAssignee: Siva Balasubramanian <sivakumar.bs>
Status: RESOLVED FIXED QA Contact:
Severity: minor    
Priority: Medium+ CC: ccasciato, randy.macleod, sivakumar.bs
Version: unspecified   
Target Milestone: 6.1 M2   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Nate Kent 2026-06-18 09:17:06 UTC
On the current master branch [1], OE-core uses a sed operation in order to add the wheel group to the sudoers file when DISTRO_FEATURES contains pam and PACKAGECONFIG contains pam-wheel [2]. This line searches for 'wheel ALL=(ALL) ALL` but the sudoers file in sudo version 1.9.17p2 does not contain that line, instead it has 'wheel ALL=(ALL:ALL) ALL' [3]. The sed fails to produce the substitute and the group is not given sudo permissions.



[1]: c2b1410faa150384562bada22c1c8f7c944c7951 at the time of writing
[2]: meta/recipes-extended/sudo/sudo_1.9.17p2.bb:40
[3]: plugins/sudoers/sudoers.in
Comment 1 Siva Balasubramanian 2026-06-18 11:22:52 UTC
I independently hit this and posted a fix before noticing Nate had already sent one. Both patches are on the oe-core list and the code change is identical:
  
  - sed -i 's/# \(%wheel ALL=(ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers
  + sed -i 's/# \(%wheel ALL=(ALL:ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers

  - Nate Kent's patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618102839.363123-1-nathan@otiv.ai/
  - My patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618110111.3484982-1-sivakumar.bs@gmail.com/

I verified the fix with a real build (DISTRO_FEATURES += "pam", PACKAGECONFIG:pn-sudo += "pam-wheel"): with the old pattern /etc/sudoers keeps # %wheel ALL=(ALL:ALL) ALL commented (bug reproduced), and with the fix it becomes %wheel 
  ALL=(ALL:ALL) ALL uncommented while the separate # %wheel ALL=(ALL:ALL) NOPASSWD: ALL line is correctly left commented. I've added Tested-by on Nate's patch.

No need for two competing patches — happy for either to land.