Skip to content

Release v2.1.1: Ubuntu 26.04 support (sudo-rs and PHP packages) - #152

Merged
jakwinkler merged 2 commits into
mainfrom
fix/2.1.1-ubuntu-2604
Sep 23, 2026
Merged

jakwinkler merged 2 commits into
mainfrom
fix/2.1.1-ubuntu-2604

Conversation

@jakwinkler

Copy link
Copy Markdown
Contributor

Fixes two failures that make MageBox unusable on a fresh Ubuntu 26.04 LTS install, both resolved by magebox bootstrap.

Passwordless sudo was completely broken

Ubuntu 26.04 ships sudo-rs, which refuses wildcards in command arguments. MageBox wrote nine such rules (systemctl start php*-fpm, cp /tmp/magebox-* /etc/nginx/nginx.conf, mkdir -p /etc/nginx/*, rm /etc/nginx/*, ln -s *, sed -i *, apt install -y blackfire*, …). One rejected rule invalidates the whole file, so /etc/sudoers.d/magebox stopped working entirely — even a plain sudo -s printed parse errors, and every MageBox operation asked for a password:

/etc/sudoers.d/magebox:8:27: wildcards are not allowed in command arguments
jakub ALL=(ALL) NOPASSWD: /usr/bin/systemctl start php*-fpm
  • Rules are now generated as complete commands, one line per PHP version and action, by a single generator in internal/bootstrap/installer/sudoers.go shared by the Ubuntu, Fedora and Arch installers. A test keeps the YAML installer definitions byte-identical to what the generator produces, so the two cannot drift again.
  • Bootstrap validates the file with visudo before installing it, and rewrites an existing file the local sudo rejects. Re-running magebox bootstrap therefore repairs a machine that upgraded into this.
  • Verified on Ubuntu 26.04: the generated file is accepted by both visudo-rs and the classic visudo (31 rules).

Security note: passwordless sudo is now limited to service control (nginx, PHP-FPM, blackfire-agent, nginx -t, nginx -s reload). Commands that only run during bootstrap or an explicit install ask for a password. This retires the old sed -i * and ln -s * rules: without a wildcard, their only equivalent allows any argument, which is unrestricted root for the MageBox user. Toggling Xdebug and configuring Blackfire now prompt.

PHP 8.1 – 8.4 could not be installed

Ondrej Sury's PPA publishes nothing for Ubuntu releases it has not caught up with. Checked live from a 26.04 machine:

Suite Release file
resolute (26.04) 404
questing (25.10) 404
plucky (25.04) 404
noble (24.04) 200

So apt had no php8.1 … php8.4 at all and only Ubuntu's own PHP 8.5 was installable. Bootstrap now asks the PPA which suites it publishes, pins the newest one, and reports the substitution:

The PHP PPA does not publish packages for resolute yet; using its noble packages instead.

A PHP version that still fails to install is reported while the rest continue, which bootstrap already did.

Also

  • Ubuntu 26.04 added to the supported releases, so it no longer warns as untested.
  • The bootstrap guide documents both behaviours, and the FAQ-style warning explains why no rule may contain a wildcard.

Verification

Check Result
go test ./... 25 packages pass
golangci-lint v2 0 issues
go vet, gofmt clean
Cross-compile darwin/arm64, linux/arm64 ok
Generated sudoers vs visudo-rs and visudo on Ubuntu 26.04 parsed OK

Not verified: whether PHP packages built for 24.04 install cleanly on 26.04. That needs a real apt run with root, which is left to the first bootstrap on the machine.

🤖 Generated with Claude Code

jakwinkler and others added 2 commits September 23, 2026 18:26
Ubuntu 26.04 ships sudo-rs, which rejects wildcards in command arguments.
Every MageBox rule of the form "systemctl start php*-fpm", "cp
/tmp/magebox-* /etc/nginx/nginx.conf" or "apt install -y blackfire*" is
refused, and because one bad rule invalidates the file, the whole of
/etc/sudoers.d/magebox stopped working: plain "sudo -s" printed parse
errors and every MageBox operation asked for a password.

Rules are now generated as complete commands from a single generator, one
line per PHP version and action, shared by the Go installers and the YAML
installer definitions; a test keeps the two in step. Bootstrap validates
the file with visudo before installing it, and rewrites an existing file
that the local sudo rejects, so re-running bootstrap repairs a machine
that upgraded into this.

Only service control stays passwordless. Commands that run during
bootstrap or an explicit install now prompt, which also retires the
"sed -i *" and "ln -s *" rules: without a wildcard their equivalent
allows any argument, which is unrestricted root for the MageBox user.

The second failure is PHP itself. Ondrej Sury's PPA publishes nothing for
Ubuntu releases it has not caught up with, so on 26.04 apt had no php8.1
through php8.4 at all. Bootstrap now asks the PPA which suites it
publishes, pins the newest one, and reports the substitution; a version
that still fails to install is reported and the rest continue.

Ubuntu 26.04 is also added to the supported releases so it no longer
warns, and the bootstrap guide documents both behaviours.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

📦 PR build artifacts

Built from fbfea5c — view run. Artifacts expire in 14 days.

Note: artifact download links require being signed in to GitHub with access to this repository.

@jakwinkler
jakwinkler merged commit 0718d02 into main Sep 23, 2026
12 checks passed
@jakwinkler
jakwinkler deleted the fix/2.1.1-ubuntu-2604 branch September 23, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant