[packages/polkit] Enable polkit-agent-helper.socket, on kernel >= 6.5 only

arekm arekm at pld-linux.org
Wed Sep 16 08:46:44 CEST 2026


commit d4979ac65926c0ffecf087b3c7ddb9bc37a260cc
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Wed Sep 16 08:31:28 2026 +0200

    Enable polkit-agent-helper.socket, on kernel >= 6.5 only
    
    (socket activated helper needs kernel with SO_PEERPIDFD; upstream issue 639)

 50-kernel-version.conf |  8 ++++++++
 polkit.spec            | 20 +++++++++++++++-----
 2 files changed, 23 insertions(+), 5 deletions(-)
---
diff --git a/polkit.spec b/polkit.spec
index 63f270d..df14027 100644
--- a/polkit.spec
+++ b/polkit.spec
@@ -18,6 +18,7 @@ License:	LGPL v2+
 Group:		Libraries
 Source0:	https://github.com/polkit-org/polkit/archive/%{version}/%{name}-%{version}.tar.gz
 # Source0-md5:	2cc95f1b02fc1de6c9e52db986642ec4
+Source1:	50-kernel-version.conf
 Patch0:		systemd-fallback.patch
 Patch1:		CVE-2026-4897.patch
 Patch2:		CVE-2026-85498.patch
@@ -64,6 +65,7 @@ Requires:	ConsoleKit >= 0.4.1
 Requires:	dbus >= 1.1.2-5
 Requires:	duktape >= 2.2.0
 %if %{with systemd}
+Requires(post,preun,postun):	systemd-units >= 38
 Requires:	systemd-units >= 38
 %else
 Provides:	user(polkitd)
@@ -158,6 +160,11 @@ rm -rf $RPM_BUILD_ROOT
 
 %meson_install
 
+%if %{with systemd}
+install -d $RPM_BUILD_ROOT%{systemdunitdir}/polkit-agent-helper.socket.d
+cp -p %{SOURCE1} $RPM_BUILD_ROOT%{systemdunitdir}/polkit-agent-helper.socket.d/
+%endif
+
 %find_lang polkit-1
 
 %clean
@@ -168,12 +175,13 @@ rm -rf $RPM_BUILD_ROOT
 %useradd -u 283 -s /bin/false -c "polkitd pseudo user" -g polkitd polkitd
 %addusertogroup polkitd proc
 
+%if %{with systemd}
+%post
+%systemd_post polkit-agent-helper.socket
+
 %preun
-# The socket-activated helper needs SO_PEERPIDFD (kernel >= 6.5) and PolkitAgentSession
-# falls back to the setuid helper only when the connect fails, so on older kernels an
-# enabled socket breaks authentication outright; the socket is therefore never enabled
-# on install, only deregistered here. https://github.com/polkit-org/polkit/issues/639
-%{?with_systemd:%systemd_preun polkit-agent-helper.socket}
+%systemd_preun polkit-agent-helper.socket
+%endif
 
 %postun
 if [ "$1" = "0" ]; then
@@ -211,6 +219,8 @@ fi
 %if %{with systemd}
 %{_prefix}/lib/sysusers.d/polkit.conf
 %{systemdunitdir}/polkit-agent-helper.socket
+%dir %{systemdunitdir}/polkit-agent-helper.socket.d
+%{systemdunitdir}/polkit-agent-helper.socket.d/50-kernel-version.conf
 %{systemdunitdir}/polkit-agent-helper at .service
 %{systemdunitdir}/polkit.service
 %{systemdtmpfilesdir}/polkit-tmpfiles.conf
diff --git a/50-kernel-version.conf b/50-kernel-version.conf
new file mode 100644
index 0000000..9bff2f9
--- /dev/null
+++ b/50-kernel-version.conf
@@ -0,0 +1,8 @@
+[Unit]
+# polkit-agent-helper-1 --socket-activated identifies its peer through SO_PEERPIDFD,
+# which the kernel gained in 6.5. Without it the helper exits without authenticating,
+# and PolkitAgentSession no longer falls back to the setuid helper once the connect
+# has succeeded, so authentication fails outright. Keeping the socket from starting
+# on older kernels leaves the setuid path in place instead.
+# https://github.com/polkit-org/polkit/issues/639
+ConditionKernelVersion=>=6.5
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/polkit.git/commitdiff/d4979ac65926c0ffecf087b3c7ddb9bc37a260cc



More information about the pld-cvs-commit mailing list