Switch Commands with update-alternatives and sudo-rs
Use update-alternatives to choose between command implementations on Ubuntu, including switching between sudo-rs and the original sudo.
On this page
Debian and Ubuntu use update-alternatives to choose which program answers to a generic command name like php, editor, or sudo. This page covers the general commands, then the most common use on current Ubuntu: switching between sudo-rs, the Rust rewrite of sudo, and the original sudo. Run the commands as root.
Manage Alternatives
List the installed providers of a command and see which one is selected:
update-alternatives --display <NAME>Choose interactively, or select a specific path:
update-alternatives --config <NAME>
update-alternatives --set <NAME> <PATH>Go back to automatic mode, where the provider with the highest priority wins:
update-alternatives --auto <NAME>Register Your Own Binary
Add a program that wasn't installed by a package, for example a PHP build installed under /opt or a LiteSpeed lsphp binary, as a provider of php:
update-alternatives --install /usr/bin/php php <PHP_BINARY> 84The arguments are the generic link, the alternative's name, the real binary, and a priority. Higher priorities win in automatic mode, and using the version number as the priority (like 84 for PHP 8.4) keeps that predictable. Check the result with php -v.
sudo-rs on Ubuntu 25.10 and Later
Starting with Ubuntu 25.10, and in Ubuntu 26.04 LTS, sudo-rs is the default sudo. The original implementation is still available as sudo.ws, and both are registered as alternatives:
update-alternatives --display sudosudo - auto mode
link best version is /usr/lib/cargo/bin/sudo
...
/usr/bin/sudo.ws - priority 40
/usr/lib/cargo/bin/sudo - priority 50Switch to the original sudo, for example if a sudoers rule depends on behavior that sudo-rs doesn't support:
update-alternatives --set sudo /usr/bin/sudo.wsSwitch back to sudo-rs:
update-alternatives --auto sudoCheck which one is active with sudo -V | head -1.
Note
sudo-rs reads the same /etc/sudoers and /etc/sudoers.d/ files, but it supports a smaller set of features. The difference you're most likely to hit is wildcards inside command arguments (such as systemctl restart app-*), which sudo-rs doesn't match. Test your rules with sudo -l -U <USER> after switching.
Install sudo-rs on Ubuntu 24.04
Ubuntu 24.04 LTS still uses the original sudo by default, but sudo-rs is available in the universe repository. It installs alongside sudo as sudo-rs, so you can try it without replacing anything:
apt install sudo-rs
sudo-rs -VTo make it answer to sudo, remove the original package and register sudo-rs as an alternative:
Warning
Keep a root shell open in a second session until you've confirmed the new sudo works. Removing sudo with no root password set or no other way in can lock you out of the server. Use apt remove, not apt purge: purging the sudo package deletes /etc/sudoers, which sudo-rs also reads.
SUDO_FORCE_REMOVE=yes apt remove sudo
update-alternatives --install /usr/bin/sudo sudo /usr/lib/cargo/bin/sudo 50SUDO_FORCE_REMOVE=yes overrides the sudo package's refusal to uninstall itself when root has no password. Then test as a normal user in the sudo group:
sudo -V | head -1
sudo id -usudo-rs 0.2.2
0To go back, run update-alternatives --remove sudo /usr/lib/cargo/bin/sudo and apt install sudo.
Sources
This article is in the public domain (CC0 1.0), code samples included. Use it however helps you.