@@ -44,7 +44,6 @@ USERADD_PARAM:${PN} = "--system --no-create-home --user-group --home-dir ${sysco
# to exclude the polkit service in favor of alternative implementations
SYSTEMD_PACKAGES += "${PN}-service"
SYSTEMD_SERVICE:${PN}-service = "${BPN}.service"
-SYSTEMD_AUTO_ENABLE = "disable"
PACKAGES =+ "${PN}-service"
RDEPENDS:${PN}-service += "polkit"
@@ -88,4 +87,7 @@ FILES:${PN} += " \
${systemd_unitdir}/system/polkit-agent-helper@.service \
"
+# Enable the polkit agent helper socket used by the systemd ask-password functionality
+SYSTEMD_SERVICE:${PN} += "polkit-agent-helper.socket"
+
CVE_STATUS[CVE-2016-2568] = "unpatched: the fix is a kernel compiled without CONFIG_LEGACY_TIOCSTI"
The polkit agent helper socket is is used for authorization requests from (among others) systemd applications that requires administrative privileges. When available, the polkit-agent-helper-1 executable doesn't need the setuid bit for authorization to work. Enable authorization without requiring setuid by configuring the systemd bbclass to enable the polkit agent helper socket at package install time. For the enablement to actually happen, the SYSTEMD_AUTO_ENABLE variable is changed back to (its default) enable value. This is okay, since it was originally assigned to not enable the polkit.service unit. That unit doesn't include an install section, so it cannot be enablet. Signed-off-by: Martin Hundebøll <martin@geanix.com> --- meta-oe/recipes-extended/polkit/polkit_127.bb | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-)