14 ms·
Memory-safe sudo to become the default in Ubuntu
- bmink 1y ago[flagged]
- dvtkrlbs 1y agoThe point of the "memory safe" sudo was not only that though. They removed a lot of nice really rarely used features to make the attack surface smaller.
- Rotundo 1y agoDid sudo have memory problems? Did it ever fail because it didn't handle its memory correctly?
- stop50 1y agoSudo had quite a few problems with security, partially because of this doas was developed for BSD. Some problems come from the huge amount of features(ldap, easter eggs, ...). sudo-rs reduces the problems by not implementing those features.
- XorNot 1y agoRemoving LDAP is a huge problem for the more important sudo deployments though: centralized management of permissions is kind of a vital function.
- Filligree 1y agoThose people can keep using sudo; it’s not going away. The rest of us get better security.
- immibis 1y agoHaving to type doas on systems without LDAP and sudo on systems with LDAP is abstraction leakage.
- fluidcruft 1y agoIs it actually removing ldap or is it offloading to pam?
- JoshTriplett 1y agoDebian is currently in the process of dropping the direct LDAP support in sudo, in favor of sssd. From sudo's NEWS.Debian.gz: > In practice, there are few installations that use sudo-ldap. Most installations that use LDAP as a directory service and sudo have now opted for sssd, sssd-ldap and libsss-sudo. > The Debian sudo team recommends the use of libsss-sudo for new installations and the migration of existing installations from sudo-ldap to libsss-sudo and sssd.
- XorNot 1y agoAh that makes more sense.
- dec0dedab0de 1y agoCould you clarify what you mean by more important sudo deployments?
- rnijveld 1y agoThe features we specifically don’t support are those related to direct LDAP support within sudo, so things like loading a sudoers file directly from LDAP. Sudo-rs will use any user retrieved via NSS, such as when configured using SSSD to load LDAP users. And from the authentication side you can use whatever PAM supports, so anything like Kerberos etc, which again can be coupled with the same LDAP database.
- ch_123 1y ago> Some problems come from the huge amount of features(ldap, easter eggs, ...). sudo-rs reduces the problems by not implementing those features. This makes me wonder: 1) Would a hypothetical "sudo-lite" with these features removed lead to better security without a rewrite? 2) If these features are useful in the real world, will a Rust rewrite of sudo inevitably gain these features over time and end up with similar problems?
- throw0101a 1y ago> 1) Would a hypothetical "sudo-lite" with these features removed lead to better security without a rewrite? OpenBSD did this with their doas utility: * https://en.wikipedia.org/wiki/Doas https://en.wikipedia.org/wiki/Doas
- Dylan16807 1y ago"without a rewrite" means cutting down the existing code. A completely different program goes into the same category as "rewrite".
- 0cf8612b2e1e 1y agodoas is 500 lines of C. Two orders is magnitude less than sudo yet still covers the core functionality. Sure you could grandfather”s axe your way into the final product, but difficult to see how a a hypothetical code base 1% of the original counted as anything but a rewrite.
- Dylan16807 1y agoYour phrasing sounds like you disagree with me, but you're saying the same thing, right? That doas is not an example of "without a rewrite".
- literalAardvark 1y agoIt can't end up with similar problems, due to the memory safety guarantee. That's not to say that it won't create other ones.
- mrweasel 1y agoUbuntu moving to a memory safe sudo implementation isn't actually that concerning to me. It's a good idea to have a smaller, safer sudo alternative as the default, as OpenBSD does with doas. Users can install sudo if they need it. My problem is that it needs to specifically be called something else than sudo. Again OpenBSD has doas, which to the users clearly isn't sudo, so users don't expect it to behave as sudo or configure as sudo. By all means, write a better, safer, smaller, more secure version of sudo, but don't have command be sudo or sudo-rs, name it something else.
- mid-kid 1y agoThere's been cases[1], of particular note, the unescape overflow one[2]. This one scathed the reputation of sudo enough to get people pushing for alternatives such as doas. The track record of vulnerabilities in general leaves a bit to be desired, even outside of memory vulns. [1]: https://www.sudo.ws/security/advisories/ https://www.sudo.ws/security/advisories/ [2]: https://www.sudo.ws/security/advisories/unescape_overflow/ https://www.sudo.ws/security/advisories/unescape_overflow/
- Maxatar 1y agoYes it has: https://nvd.nist.gov/vuln/detail/cve-2021-3156 https://nvd.nist.gov/vuln/detail/cve-2021-3156
- ndegruchy 1y agoSeems like the trifecta group is /just/ about migrating tools to rust? Am I understanding that right? I don't have a problem with it, specifically. Seems odd that they don't advertise it, though.
- homefree 1y ago[flagged]
- Ygg2 1y ago> The religious element of rust programmers Yeah. I too, hate the Rust Evangelically Orthodox Later Day Christians. Oh, wait... You're serious. What is religious about rewriting tools in Rust? Isn't that what most programmers do for fun and learning? Is it any more religious than worshiping Alan Kay or Dijkstra? > It makes me wonder how much is motivated by stuff other than what’s actually the best outcome. Looks in the thread... Sees https://www.sudo.ws/security/advisories/ https://www.sudo.ws/security/advisories/ Are you sure the status quo is the better outcome?
- kjrfghslkdjfl 1y ago[dead]
- ziddoap 1y ago>What is religious about rewriting tools in Rust? "Religious" isn't being used to refer to people rewriting tools in Rust. It's used to refer to people zealously commenting on message boards that every single tool ever built should be rewritten in Rust, and if you aren't rewriting your tool in Rust, you're an idiot.
- Ygg2 1y ago> It's used to refer to people zealously commenting on message boards that every single tool ever built should be rewritten in Rust. Ok, but between me, GP and the article, who said that? Where are the Rabid RIIR fans? And before you misquote me, I said, why wouldn't you rewrite stuff in Rust, if the status quo is ridden with bugs, and safety issues? And why shouldn't a Linux distro switch to it if they desire.
- kokada 1y agoI am not sure if memory-safety is the biggest issue in sudo design. I find the fact that it is a setuid binary a much bigger issue because a bug can possible result in privilege escalation. I found an alternative implementation that doesn't rely in being a setuid binary like systemd-run0 much more interesting from a security perspective, but I am no security expert.
- deleted 1y ago[deleted]
- Retr0id 1y agoA bug in a daemon-based sudo alternative would surely also result in privilege escalation? I think the main benefit of eliminating setuid binaries is that you can forbid them system-wide (e.g. via mount flags), as a hardening measure.
- JoshTriplett 1y agoThere's value in always starting processes from a known-secure environment rather than attempting to transform a user's arbitrary environment into a secure one.
- Retr0id 1y agoTrue, CVE-2021-4034 comes to mind as a recent example (exploiting zero-length argv)
- hedora 1y agoHow is that any different than a daemon that has a parser error in its message handler, except that the daemon could be misconfigured to listen on a network socket? The original unix process abstraction was extremely simple; the entire spec is a few pages. The problem is that Linux keeps adding more and more levels of Rube Goldberg machine to its security model, so now literally no one understands how a default minimal install of, say, Ubuntu works. Adding a magic daemon that runs stuff as root to this pile of complexity probably won’t help. Ripping out almost all the cruft that’s accumulated over the years, and adding back something sane (maybe BSD jails) would work a lot better.
- dev_l1x_be 1y agodoas is a much simpler (and therefore better) alternative.
- JoshTriplett 1y agodoas is not a compatible drop-in replacement for existing users.
- hedora 1y agoI wonder if there’s one that hardcodes a simple policy like “members of the wheel group can run any command with a password, and a 5 minute timeout”, but is also sudo command line compatible. That’s what 99% of distros default to, and it’s simple.
- dev_l1x_be 1y agoI did not claim that. Here is my doas config: cat /etc/doas.conf permit nopass jane as root It be read and understood without prior knowledge. Sudo: #ALL ALL = (root) NOPASSWD: C_ZFS I have no idea what is going here, not sure what ALL means, why root is in (), etc.
- 778464636 1y agoNeither is sudo-rs. From TFA: > some features of the original sudo will not be implemented in sudo-rs if they serve only highly niche use cases
- badgersnake 1y agoFor my limited use case, alias sudo=doas seems to work fine.
- Foxboron 1y agodoas is a really bad option on Linux. The Linux port has not been maintained for 3 years. Has unmerged rowhammer fixes and generally a yolo auth system best described as "dangerous". You are better off using a well maintained project, that includes the CVEs^Wwarts. It's a mistake to think that `doas` on Linux is the same as `doas` on BSD.
- asmodeuslucifer 1y agoThat's good to hear.
- bpierre 1y agoHow does sudo-rs compare to run0? https://news.ycombinator.com/item?id=40205714 https://news.ycombinator.com/item?id=40205714
- paulddraper 1y agoA trivial Google search answers that. run0 requires systemd-type OS.
- ranger207 1y agoGiven that Ubuntu uses systemd like the vast majority of Linux systems nowadays, how does sudo-rs differ from run0?
- fweimer 1y agoYou might not have a systemd instance inside a container, but you still might want to switch user IDs there.
- Vilian 1y agoPodman has systemd inside, you can run0 in it
- yjftsjthsd-h 1y agoNot all containers are on podman
- fweimer 1y agoSurely that depends on the container? Podman doesn't artificially inject a systemd process as PID 1 by default.
- hedora 1y agosudo-rs doesn’t gratuitously require a root privilege daemon that regularly ships filesystem destruction and remote unauthenticated arbitrary code execution bugs. If your bar is “I’ll tolerate such crap”, you may as well run your desktop session as root.
- Gabrys1 1y ago> Ubuntu is the most widely deployed Linux operating system Nitpicking, but I thought Android was the most widely deployed Linux OS around...
- xethos 1y ago[flagged]
- jbverschoor 1y agoUbuntu is the most widely deployed Ubuntu operating system
- bheadmaster 1y ago> we do not need a flame war or chain of comments about what RMS' valid points were, when he was being (tremendously but unintentionally) offensive, and when he was merely being overly pedantic If your intention is to not start a flame war, you might want to avoid contraversial topics such as the obviously manufactured canceling of RMS by the-powers-that-be.
- fsflover 1y agoAnd if you do want to see some flame war about the real RMS cancelling, here you go: https://news.ycombinator.com/item?id=22299156 https://news.ycombinator.com/item?id=22299156
- bheadmaster 1y agoYeah, I remember that. That canceling was exactly what I referred to. I didn't mean to imply that the canceling was fake by putting it in the quotes, but that it was intentional and orchestrated. I've removed the quotes to avoid further misunderstanding.
- pphysch 1y agoMaybe "deployed" is the key word here. Android is treated like a fixture of mobile devices rather than a fungible Linux distro.
- zamalek 1y agoI have been using sudo-rs for over a year. The only issue that I've had is running into `-E` being unsupported once every few months - which is arguably a good thing because I shouldn't be naughty and allow arbitrary envs to leak into a privileged session.
- xvilka 1y agoNext they should adopt uutils[1] as coreutils, findutils, diffutils, etc alternative. [1] http://github.com/uutils/ http://github.com/uutils/
- steveklabnik 1y agoThey are: https://jnsgr.uk/2025/03/carefully-but-purposefully-oxidising-ubuntu/ https://jnsgr.uk/2025/03/carefully-but-purposefully-oxidisin...
- mfld 1y agoRelated discussion from 2 months ago: https://news.ycombinator.com/item?id=43403821 https://news.ycombinator.com/item?id=43403821
- bArray 1y ago> This move is part of a broader effort by Canonical to improve the resilience and maintainability of core system components. Sudo-rs is developed by the Trifecta Tech Foundation (TTF), a nonprofit organization that creates secure, open source building blocks for infrastructure software. Ubuntu continuously updates itself without permission, killing apps and losing previous state. You have the Javascript based Gnome window manager that is always bugging out. The Ubuntu packages, drivers and kernel are laughably behind Debian and even further behind mainline. Ubuntu continues to morph into something I don't believe in. That all said, Rust is not a smoking gun for incorrect application logic. It could still happily incorrectly execute stuff with the wrong permissions or blow something up badly. I think it's also a bad idea to offer it as a drop-in replacement when clearly features are still missing since a long time [1]. [1] https://github.com/trifectatechfoundation/sudo-rs/issues?page=2 https://github.com/trifectatechfoundation/sudo-rs/issues?pag...
- wkat4242 1y agoI think you mean a magic bullet instead of a smoking gun :)
- bArray 1y agoI meant "smoking gun" from a cyber security perspective, i.e. the conclusion or the final part of the investigation. "magic bullet" would also work here too though.
- MaKey 1y agoEvidence, particularly of a crime, that is difficult or impossible to dispute. [1] Even with your explanation I don't think it fits here. [1] https://en.m.wiktionary.org/wiki/smoking_gun https://en.m.wiktionary.org/wiki/smoking_gun
- nmstoker 1y agoYou seem to have inferred the wrong meaning of "smoking gun" and that's why your usage above doesn't make sense. There's no valid reason cyber security people would take a well known idiom and repurpose it as you imply, and a quick Google suggests they haven't done this.
- rbanffy 1y agoWhat are the implications of the license not being GPL?
- steveklabnik 1y agosudo is already (basically) MIT licensed https://www.sudo.ws/about/license/ https://www.sudo.ws/about/license/
- rbanffy 1y agoOh well. Completely forgot about that.
- johnklos 1y ago"This move is part of a broader effort by Canonical to improve the resilience and maintainability of core system components." Somehow "maintainability" has never been something I'd ever associate with Ubuntu. Is it a reference to their source tree? That'd make a lot more sense than if they were referring to the OS itself.
- figomore 1y agosudo-rs is already default AerynOS (SerpentOS).