We're reverting back from doas to sudo, this time choosing sudo-rs as our implementation.
Read our latest blog post for our reasoning.

https://postmarketos.org/edge/2026/03/18/sudo-rs-instead-of-doas/

New postmarketOS installations now by default use sudo-rs instead of doas

Aiming for a 10 year life-cycle for smartphones

postmarketOS

@postmarketOS leaving doas for sudo-rs for security is a bit of a wild take

sudo-rs is the least secure of the three, as of this moment

@SRAZKVT @postmarketOS I wonder how you'd support that claim

@natty @postmarketOS sudo-rs is new and doesn't have the history of bugfixes of sudo, and doas is much simpler in design than either of the two others, therefore having a smaller and more straightforward codebase

even without any vulnerability, a sudo implementation will always be less secure than something like doas, as the config format is significantly more complex, and therefore more prone to user errors