On the current master branch [1], OE-core uses a sed operation in order to add the wheel group to the sudoers file when DISTRO_FEATURES contains pam and PACKAGECONFIG contains pam-wheel [2]. This line searches for 'wheel ALL=(ALL) ALL` but the sudoers file in sudo version 1.9.17p2 does not contain that line, instead it has 'wheel ALL=(ALL:ALL) ALL' [3]. The sed fails to produce the substitute and the group is not given sudo permissions. [1]: c2b1410faa150384562bada22c1c8f7c944c7951 at the time of writing [2]: meta/recipes-extended/sudo/sudo_1.9.17p2.bb:40 [3]: plugins/sudoers/sudoers.in
I independently hit this and posted a fix before noticing Nate had already sent one. Both patches are on the oe-core list and the code change is identical: - sed -i 's/# \(%wheel ALL=(ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers + sed -i 's/# \(%wheel ALL=(ALL:ALL) ALL\)/\1/' ${D}${sysconfdir}/sudoers - Nate Kent's patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618102839.363123-1-nathan@otiv.ai/ - My patch: https://patchwork.yoctoproject.org/project/oe-core/patch/20260618110111.3484982-1-sivakumar.bs@gmail.com/ I verified the fix with a real build (DISTRO_FEATURES += "pam", PACKAGECONFIG:pn-sudo += "pam-wheel"): with the old pattern /etc/sudoers keeps # %wheel ALL=(ALL:ALL) ALL commented (bug reproduced), and with the fix it becomes %wheel ALL=(ALL:ALL) ALL uncommented while the separate # %wheel ALL=(ALL:ALL) NOPASSWD: ALL line is correctly left commented. I've added Tested-by on Nate's patch. No need for two competing patches — happy for either to land.
https://git.openembedded.org/openembedded-core/commit/?id=76231f202a437be221c2580d4fa0fc100c453e92