In Ubuntu 25.10, an alternative to sudo written in Rust will be used

Canonical plans to use an alternative to the sudo utility, developed by the sudo-rs project and written in Rust, by default in the upcoming release of Ubuntu 25.10. In March, a similar decision was made regarding the replacement of GNU Coreutils utilities with the uutils toolset. Initiatives are currently under consideration to replace zlib and ntpd with zlib-rs and ntpd-rs, as well as to use Sequoia instead of GnuPG in the APT package manager.

The sudo-rs utility is designed to be compatible with classic sudo and su utilities whenever possible, allowing users to transparently replace sudo with sudo-rs in most usage scenarios. For users who prefer not to switch to uutils and sudo-rs, Ubuntu 25.10 will provide an option to revert to the classic versions of coreutils and sudo system utilities.

You can test the use of sudo-rs without waiting for the release of Ubuntu 25.10 by using the oxidizr toolset. Currently, experiments are available in oxidizr for switching to the default use of the uutils coreutils, uutils findutils, uutils diffutils, and sudo-rs packages. For example, to replace sudo on your system, simply run the command “sudo oxidizr enable —experiments sudo-rs”, and to revert to the original state, use the command “oxidizr disable”.

The replacement of system components is part of an initiative to enhance the quality of the system environment by supplying programs that are initially developed with a focus on security, reliability, and correctness. Delivering utilities written in Rust will reduce the risk of memory errors, such as accessing freed memory and buffer overflows. If the experiment proves successful, Rust utilities will be used by default in the LTS branch of Ubuntu 26.04.

The announcement also mentions that Canonical is working on enhancing the capabilities of sudo-rs and uutils. Among the tasks planned for implementation in sudo-rs before the release of Ubuntu 25.10 are: the implementation of the NOEXEC mode, adding support for AppArmor profiles, creating the sudoedit utility, and ensuring support for older Linux kernels (older than release 5.9). The NOEXEC mode will allow the blocking of child process execution for applications run through sudo by filtering system calls execve and execveat. Among the sponsored improvements by Canonical in uutils, there is mention of adding SELinux support in common utilities like mv, ls, and cp, as well as adding internationalization support in utilities (for example, the sort utility does not fully support locale parameters).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster