| Summary: | Enabling `pam-wheel` does not allow add wheel to sudoers | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Nate Kent <yocto> |
| Component: | oe-core other | Assignee: | Siva Balasubramanian <sivakumar.bs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | minor | ||
| Priority: | Medium+ | CC: | ccasciato, randy.macleod, sivakumar.bs |
| Version: | unspecified | ||
| Target Milestone: | 6.1 M2 | ||
| Hardware: | All | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Nate Kent
2026-06-18 09:17:06 UTC
I independently hit this and posted a fix before noticing Nate had already sent one. Both patches are on the oe-core list and the code change is identical:
- sed -i 's/# \(%wheel ALL=(ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers
+ sed -i 's/# \(%wheel ALL=(ALL:ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers
- Nate Kent's patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618102839.363123-1-nathan@otiv.ai/
- My patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618110111.3484982-1-sivakumar.bs@gmail.com/
I verified the fix with a real build (DISTRO_FEATURES += "pam", PACKAGECONFIG:pn-sudo += "pam-wheel"): with the old pattern /etc/sudoers keeps # %wheel ALL=(ALL:ALL) ALL commented (bug reproduced), and with the fix it becomes %wheel
ALL=(ALL:ALL) ALL uncommented while the separate # %wheel ALL=(ALL:ALL) NOPASSWD: ALL line is correctly left commented. I've added Tested-by on Nate's patch.
No need for two competing patches — happy for either to land.
|