diff mbox series

[meta-oe] polkit: fix /etc/polkit-1/rules.d permissions

Message ID 20260929234420.876217-1-sergio.prado@e-labworks.com
State Accepted
Headers show
Series [meta-oe] polkit: fix /etc/polkit-1/rules.d permissions | expand

Commit Message

Sergio Prado Sept. 29, 2026, 11:44 p.m. UTC
The recipe installs /etc/polkit-1/rules.d as polkitd:root 0700, but
polkit's own tmpfiles.d entry declares it as root:polkitd 0750:

  d /etc/polkit-1/rules.d 0750 root polkitd - -

As a result, systemd-tmpfiles changes the ownership and mode of the
directory at every boot, and on a read-only root filesystem it fails
with:

  systemd-tmpfiles[241]: fchownat() of /etc/polkit-1/rules.d failed: Read-only file system

The polkitd:root 0700 ownership was added to avoid rpm conflicts with the
polkit-group-rule-* packages, which no longer install into /etc since
commit d5e90541f8e3.

Match upstream instead. This is also the stricter setting, as polkitd
can read the rules but cannot modify them.

Signed-off-by: Sergio Prado <sergio.prado@e-labworks.com>
---

Tested on master with qemux86-64, systemd, package_rpm and a read-only
rootfs, with polkit and all three polkit-group-rule-* packages installed:
do_rootfs succeeds, the fchownat() error is gone, and polkitd still
loads rules from /etc/polkit-1/rules.d.

Please consider this for backport to wrynose as well.

 meta-oe/recipes-extended/polkit/polkit_127.bb | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)
diff mbox series

Patch

diff --git a/meta-oe/recipes-extended/polkit/polkit_127.bb b/meta-oe/recipes-extended/polkit/polkit_127.bb
index 91be8858cd0f..10b3fbfe47f0 100644
--- a/meta-oe/recipes-extended/polkit/polkit_127.bb
+++ b/meta-oe/recipes-extended/polkit/polkit_127.bb
@@ -61,10 +61,10 @@  FILES:${PN}-dbus += "\
 "
 
 do_install:append() {
-	#Fix up permissions on polkit rules.d to work with rpm4 constraints
+	# Match the ownership and mode set by polkit's own tmpfiles.d entry
 	if ${@bb.utils.contains('PACKAGECONFIG', 'libs-only', 'false', 'true', d)}; then
-		chmod 700 ${D}/${sysconfdir}/polkit-1/rules.d
-		chown polkitd:root ${D}/${sysconfdir}/polkit-1/rules.d
+		chmod 750 ${D}/${sysconfdir}/polkit-1/rules.d
+		chown root:polkitd ${D}/${sysconfdir}/polkit-1/rules.d
 	fi
 
 	# Polkit unconditionally installs a systemd service, remove it on SysVinit