5 ms·
I'm curious, is this one implementation of sudo really used everywhere? I was under the impression that different Linux userspaces sometimes implement these co
by 2bitencryption 6y ago
I'm curious, is this one implementation of sudo really used everywhere?
I was under the impression that different Linux userspaces sometimes implement these common commands differently. Like "ls" sometimes actually being aliased to a bash script, or maybe BSD having one implementation and Ubuntu another. Is that not the case? Is "sudo" not maintained by an entity like gnu, bsd, etc?
edit - in other words, I always assumed "sudo" was a highly-dependent system-level tool, not just some useful helper binary that is maintained by one independent person.
- sigio 6y agoNope... sudo is just this sudo in 99.99% of the cases. There are some alternatives, such as *bsd's doas, and others, but all but doas and su are so non-popular and outdated that I would not recommend using them, as they probably have way more security issues.
- wahern 6y agodoas is just OpenBSD. You can install doas from ports on NetBSD or FreeBSD, just like you can install doas on Linux. OpenBSD dropped sudo from the base OS several years ago. sudo just became too complex, tailored to the feature creep demanded and required (PAM, ugh) by Linux users.
- turminal 6y agoBriefly going through their website (sudo.ws) I am seriously wondering why anyone would want to put some of those features in a privilege management tool.
- wahern 6y agoTodd Miller is a sharp developer and core OpenBSD contributor. I can only imagine the deluge of requests and pressure he faces to expand sudo. There's no end to the crazy stuff corporations demand, especially when it comes to integration--audit, logging, ldap, etc.
- toyg 6y ago> Todd Miller is a sharp developer and core OpenBSD contributor. I wonder why OpenBSD wrote their own version. Could it be that, knowing how the sausage is made, they thought it was better to have a salad...?
- krylon 6y ago> I wonder why OpenBSD wrote their own version. With most other projects, I would smell a major case of Not-Invented-Here, but the OpenBSD developers seem to have an impressive track record of actually learning from mistakes, both from their own and those made by others. > knowing how the sausage is made, they thought it was better to have a salad I love that phrase! (Coincidentally, an engineer working in food processing once explained to me how chicken nuggets are made (while we were eating!), I have mostly avoided them ever since...)
- masklinn 6y ago> I wonder why OpenBSD wrote their own version. Wonder no more: https://flak.tedunangst.com/post/doas https://flak.tedunangst.com/post/doas > I started working on doas quite some time ago after some personal issues with the default sudo config. The “safe environment” was under constant revision and I regularly found myself unable to run pkg_add or build a flavored port or whatever because the expected variables were being excised from the environment. If I had been paying attention, keeping sudoers up to date probably would not have been such an ordeal, but I don’t like change. > The core of the problem was really that some people like to use sudo to build elaborate sysadmin infrastructures with highly refined sets of permissions and checks and balances. Some people (me) like to use sudo to get a root shell without remembering two passwords. > […] > Talking with deraadt and millert, however, I wasn’t quite alone. There were some concerns that sudo was too big, running too much code in a privileged process. And there was also pressure to enable even more options, because the feature set shipped in base wasn’t big enough. (As shipped in OpenBSD, the compiled sudo was already five times larger than just about any other setuid program.) Hurray, tension. It wasn’t the problem I was trying to solve, but it was an opening from which to launch my diabolical plan.
- acct776 6y agodoas has a much smaller attack surface, and is worth checking out.
- bawolff 6y agoWikipedia has a history section https://en.wikipedia.org/wiki/Sudo#History https://en.wikipedia.org/wiki/Sudo#History But every tool has to be maintained by someone. Its not like GNU is a faceless corporation.
- TheDong 6y ago> Like "ls" sometimes actually being aliased to a bash script, or maybe BSD having one implementation and Ubuntu another It is true that BSD and linux sometimes have different implementations of posix commands. The vast majority of linux distros are using the same gnu coreutils though. There are alternate implementations (like busybox, among others), but they're not often used in desktop distros. I'm curious if you have any example of a linux distro that does treat ls so weirdly; that uses anything other gnu coreutils or busybox for it.
- Arnavion 6y agoThey probably didn't mean replace wholesale, but that `ls` in a shell is a wrapper around the underlying coreutils `ls` with some extra flags by default. Eg: $ (. /etc/os-release; echo "$NAME:$VERSION_ID") openSUSE Tumbleweed:20210121 $ command -v ls alias ls='_ls' $ grep -A6 -B1 '_ls ()' /etc/profile.d/ls.bash bash|dash|ash) _ls () { local IFS=' ' command ls $LS_OPTIONS ${1+"$@"} } alias ls=_ls ;;