Repository navigation
Release v2.1.1: Ubuntu 26.04 support (sudo-rs and PHP packages) - #152
Merged
Merged
Conversation
Ubuntu 26.04 ships sudo-rs, which rejects wildcards in command arguments. Every MageBox rule of the form "systemctl start php*-fpm", "cp /tmp/magebox-* /etc/nginx/nginx.conf" or "apt install -y blackfire*" is refused, and because one bad rule invalidates the file, the whole of /etc/sudoers.d/magebox stopped working: plain "sudo -s" printed parse errors and every MageBox operation asked for a password. Rules are now generated as complete commands from a single generator, one line per PHP version and action, shared by the Go installers and the YAML installer definitions; a test keeps the two in step. Bootstrap validates the file with visudo before installing it, and rewrites an existing file that the local sudo rejects, so re-running bootstrap repairs a machine that upgraded into this. Only service control stays passwordless. Commands that run during bootstrap or an explicit install now prompt, which also retires the "sed -i *" and "ln -s *" rules: without a wildcard their equivalent allows any argument, which is unrestricted root for the MageBox user. The second failure is PHP itself. Ondrej Sury's PPA publishes nothing for Ubuntu releases it has not caught up with, so on 26.04 apt had no php8.1 through php8.4 at all. Bootstrap now asks the PPA which suites it publishes, pins the newest one, and reports the substitution; a version that still fails to install is reported and the rest continue. Ubuntu 26.04 is also added to the supported releases so it no longer warns, and the bootstrap guide documents both behaviours. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes two failures that make MageBox unusable on a fresh Ubuntu 26.04 LTS install, both resolved by
magebox bootstrap.Passwordless sudo was completely broken
Ubuntu 26.04 ships sudo-rs, which refuses wildcards in command arguments. MageBox wrote nine such rules (
systemctl start php*-fpm,cp /tmp/magebox-* /etc/nginx/nginx.conf,mkdir -p /etc/nginx/*,rm /etc/nginx/*,ln -s *,sed -i *,apt install -y blackfire*, …). One rejected rule invalidates the whole file, so/etc/sudoers.d/mageboxstopped working entirely — even a plainsudo -sprinted parse errors, and every MageBox operation asked for a password:internal/bootstrap/installer/sudoers.goshared by the Ubuntu, Fedora and Arch installers. A test keeps the YAML installer definitions byte-identical to what the generator produces, so the two cannot drift again.visudobefore installing it, and rewrites an existing file the local sudo rejects. Re-runningmagebox bootstraptherefore repairs a machine that upgraded into this.visudo-rsand the classicvisudo(31 rules).Security note: passwordless sudo is now limited to service control (nginx, PHP-FPM, blackfire-agent,
nginx -t,nginx -s reload). Commands that only run during bootstrap or an explicit install ask for a password. This retires the oldsed -i *andln -s *rules: without a wildcard, their only equivalent allows any argument, which is unrestricted root for the MageBox user. Toggling Xdebug and configuring Blackfire now prompt.PHP 8.1 – 8.4 could not be installed
Ondrej Sury's PPA publishes nothing for Ubuntu releases it has not caught up with. Checked live from a 26.04 machine:
So apt had no
php8.1…php8.4at all and only Ubuntu's own PHP 8.5 was installable. Bootstrap now asks the PPA which suites it publishes, pins the newest one, and reports the substitution:A PHP version that still fails to install is reported while the rest continue, which bootstrap already did.
Also
Verification
go test ./...go vet,gofmtvisudo-rsandvisudoon Ubuntu 26.04Not verified: whether PHP packages built for 24.04 install cleanly on 26.04. That needs a real
aptrun with root, which is left to the first bootstrap on the machine.🤖 Generated with Claude Code