diff mbox series

polkit: enable the agent helper socket

Message ID 20261008125051.619349-1-martin@geanix.com
State New
Headers show
Series polkit: enable the agent helper socket | expand

Commit Message

Martin Hundebøll Oct. 8, 2026, 12:50 p.m. UTC
The polkit agent helper socket is is used for authorization requests
from (among others) systemd applications that requires administrative
privileges. When available, the polkit-agent-helper-1 executable doesn't
need the setuid bit for authorization to work.

Enable authorization without requiring setuid by configuring the systemd
bbclass to enable the polkit agent helper socket at package install
time.

For the enablement to actually happen, the SYSTEMD_AUTO_ENABLE variable
is changed back to (its default) enable value. This is okay, since it
was originally assigned to not enable the polkit.service unit. That unit
doesn't include an install section, so it cannot be enablet.

Signed-off-by: Martin Hundebøll <martin@geanix.com>
---
 meta-oe/recipes-extended/polkit/polkit_127.bb | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)
diff mbox series

Patch

diff --git a/meta-oe/recipes-extended/polkit/polkit_127.bb b/meta-oe/recipes-extended/polkit/polkit_127.bb
index 10b3fbfe47f0..20891528262e 100644
--- a/meta-oe/recipes-extended/polkit/polkit_127.bb
+++ b/meta-oe/recipes-extended/polkit/polkit_127.bb
@@ -44,7 +44,6 @@  USERADD_PARAM:${PN} = "--system --no-create-home --user-group --home-dir ${sysco
 # to exclude the polkit service in favor of alternative implementations
 SYSTEMD_PACKAGES += "${PN}-service"
 SYSTEMD_SERVICE:${PN}-service = "${BPN}.service"
-SYSTEMD_AUTO_ENABLE = "disable"
 
 PACKAGES =+ "${PN}-service"
 RDEPENDS:${PN}-service += "polkit"
@@ -88,4 +87,7 @@  FILES:${PN} += " \
 	${systemd_unitdir}/system/polkit-agent-helper@.service \
 "
 
+# Enable the polkit agent helper socket used by the systemd ask-password functionality
+SYSTEMD_SERVICE:${PN} += "polkit-agent-helper.socket"
+
 CVE_STATUS[CVE-2016-2568] = "unpatched: the fix is a kernel compiled without CONFIG_LEGACY_TIOCSTI"