From d2e40364308a9487926449d0bb1cba642b882469 Mon Sep 17 00:00:00 2001 From: Markus Pesch Date: Thu, 10 Sep 2026 21:07:58 +0200 Subject: [PATCH] fix(tasks): match @includedir directive in /etc/sudoers The regular expression required a leading hash, but sudo 1.9.1 introduced @includedir and distributions such as Debian 12, Ubuntu 22.04, RHEL 9 and Arch Linux ship /etc/sudoers with that syntax. Since the existing line was never matched, lineinfile appended a second directive and /etc/sudoers.d was included twice. The dot in sudoers.d is escaped as well, so the expression no longer matches unrelated paths. Co-authored-by: Copilot --- tasks/main.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tasks/main.yaml b/tasks/main.yaml index cf55eca..16aeebb 100644 --- a/tasks/main.yaml +++ b/tasks/main.yaml @@ -34,7 +34,8 @@ ansible.builtin.lineinfile: dest: /etc/sudoers state: present - regexp: "^(#)+(\\s)*includedir(\\s)*/etc/sudoers.d" + # sudo >= 1.9.1 ships the directive as @includedir, older releases as #includedir + regexp: "^[#@]+(\\s)*includedir(\\s)*/etc/sudoers\\.d" line: "#includedir /etc/sudoers.d" validate: 'visudo --check --file %s' mode: "0440"