121 Commits

Author SHA256 Message Date
c0b836a01e Accepting request 1328198 from home:msmeissn:branches:Base:System
- change to /var/lib/polkit-1 being tmpfiles created (jsc#PED-14794)

OBS-URL: https://build.opensuse.org/request/show/1328198
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=210
2026-01-21 09:08:14 +00:00
78948b7b6e Accepting request 1325956 from home:msmeissn:branches:Base:System
- Updated to version 127:
  - socket-activated polkit-agent-helper can now run without SETUID (Luca Boccassi)
  - user id (UID) now accessible to JavaScript rules via subject.uid (Rosentti, Jan Rybar)
  - INI config file support for polkitd with configurable auth expiration timer (Luca Boccassi)
  - auth_keep: skip re-authentication if new process shares same UID/parent/cgroup/tty (Luca Boccassi)
  - CheckAuthorization now returns 'polkit.result' in the details dict (Luca Boccassi)
  - pkexec: set $SUDO_UID/$SUDO_GID for compatibility with sudo (Lennart Poettering)
  - pkexec: use realpath when comparing org.freedesktop.policykit.exec.path (Walter Doekes)
  - memory limits added to systemd unit to mitigate memory leaks (Alexander Meshcheryakov)
  - new translations: Bulgarian (twlvnn kraftwerk), Occitan (Mejans)
- systemd-socket-activation.patch: upstream, removed
- auth_keep.patch: upstream, removed
- sudo_uid.patch: upstream, removed
- added polkitd.conf.5 manpage, added polkitd.conf

OBS-URL: https://build.opensuse.org/request/show/1325956
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=207
2026-01-08 12:49:43 +00:00
8a41cf2b0d Accepting request 1315266 from home:kukuk:pwaccess
- Backport for NoNewPrivs support:
  - systemd-socket-activation.patch: start agent via socket, no setuid
- Backport of patches for better run0 usability:
  - auth_keep.patch: do not ask for reauth if new process shares same UID/parent/cgroup/tty
  - sudo_uid.patch: also set $SUDO_UID/$SUDO_GID for compat with sudo

OBS-URL: https://build.opensuse.org/request/show/1315266
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=205
2025-11-03 10:39:07 +00:00
31741dfaa4 Accepting request 1305226 from home:Andreas_Schwab:Factory
- Skip tests in qemu emulation

OBS-URL: https://build.opensuse.org/request/show/1305226
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=203
2025-09-16 15:36:12 +00:00
cfdf3d3404 Accepting request 1304764 from home:msmeissn:branches:Base:System
- change /etc/polkit-1/rules.d group ownership back to polkitd 
  (bsc#1249581)

OBS-URL: https://build.opensuse.org/request/show/1304764
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=202
2025-09-15 09:41:54 +00:00
OBS User buildservice-autocommit
e494408873 Updating link to change in openSUSE:Factory/polkit revision 94
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=5b9b8309cc5f90bbc924f7a9bdf514c5
2025-09-12 07:32:53 +00:00
74a78b2a85 Accepting request 1303228 from home:msmeissn:branches:Base:System
- revert upstream change to have /etc/polkit-1/rules.d as tempdir

OBS-URL: https://build.opensuse.org/request/show/1303228
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=199
2025-09-08 14:36:47 +00:00
5e9987fd46 Accepting request 1302995 from home:msmeissn:branches:Base:System
- store our defaults in /usr/share/ as /etc/polkit is now a tempdir

OBS-URL: https://build.opensuse.org/request/show/1302995
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=198
2025-09-06 08:47:20 +00:00
29c7235525 Accepting request 1302945 from home:msmeissn:branches:Base:System
- Updated to version 126:
  + Highlights:
    - many code fixes detected either by CI or the author himself (Frantisek Sumsal)
    - shellcheck and dependabot integration (Jan Macku)
    - search for rules in /usr/local/share rather than /usr/local/lib (Luca Boccassi)
    - Implement LogControl1 protocol for dynamic log level changes (Luca Boccassi)
    - read actions also from /etc/, /run/ and /usr/local/share/ (Luca Boccassi)
    - mozjs dropped in favor of duktape (Xi Ruoyao)
    - many other fixes in build system and polkit code (Many thanks to all the authors.)
- Updated to version 125:
  + Highlights:
    - introduction of CodeQL and a new integration test suite (Frantisek Sumsal)
    - dropped mocklibc (Frantisek Sumsal)
    - syslog-style log-levels introduction (Jan Rybar)
    - LogControl integration (Luca Boccassi)
    - pkexec: "No session for cookie" finally fixed (huxiaodong)
    - resources optimizations: only instances affected by sessions-change recalculate authorizations (Jan Rybar, thanks to Michal Sekletar and Milan Crha)
    - meson tweaks (Alyssa Ross, Luca Boccassi, Michael Biebl, Michael Olbrich)
    - build warnings cleanup (peelz)
    - Packit service configuration for the new upstream platform (Vincent Mihalkovic)
    - systemd-tmpfiles.d integration (Vincent Mihalkovic)
    - other fixes and changes (Gleb Popov, heather7283, Tianyu Chen, Tobias Stoeckmann)
    - internationalization: Slovenian (filmsi), Hindi (Scrambled777)
- Updated to version 124:
  + Highlights:
    - PIDFDs are used if available to track processes
    - pidfd parameter available for CheckAuthorization()
    - systemd-sysuser enabled for polkit
- polkit-actions-in-etc.patch: done upstream in commit 9958c259f82b066f613d171d2934c1bd829e31a4
- polkit-fix-implicit.patch: not needed anymore

OBS-URL: https://build.opensuse.org/request/show/1302945
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=197
2025-09-05 15:12:14 +00:00
f31b7b30bd Accepting request 1193874 from home:dimstar:Factory
- BuildRequire gettext-devel instead of gettext: Allows OBS to
  shortcut throught gettext-runtime-mini.

OBS-URL: https://build.opensuse.org/request/show/1193874
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=195
2024-08-14 12:50:59 +00:00
eca3cbd3a7 Accepting request 1187079 from home:jamborm:gcc14fixes
- Add -Wno-error=implicit-function-declaration to %optflags to
  work-around an issue in mocklibc (which has been meanwhile removed
  by upstream) with exactly this kind of issue.

If the request is OK, please forward it to Factory soon-ish so that we
can switch the default compiler.

OBS-URL: https://build.opensuse.org/request/show/1187079
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=193
2024-07-12 13:08:58 +00:00
d2c9b0eaab Accepting request 1132569 from home:tobijk:branches:Base:System
- Add 'dbus-service' as Requires instead of /usr/bin/dbus-daemon
  This allow to use other dbus implementations such as dbus-broker with this
  package again. (bsc#1217863)

OBS-URL: https://build.opensuse.org/request/show/1132569
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=191
2023-12-12 08:40:24 +00:00
f163fe3de5 - better safety with deeper restriction of the configuration
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=189
2023-11-20 09:44:30 +00:00
51a16a0212 - better safety with deeper resrtiction of the configuration
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=188
2023-11-20 07:57:15 +00:00
c0662bea55 Accepting request 1114786 from home:iznogood:branches:Base:System
Bump and tweaks

OBS-URL: https://build.opensuse.org/request/show/1114786
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=187
2023-10-03 08:40:00 +00:00
c4640c4fac Accepting request 1112287 from home:lnussel:branches:Base:System
- change /usr/share/polkit-1/rules.d to 555,root:root. /usr content
  isn't secret anyway so this avoids non-root owned files in /usr
  (boo#1215482)
- update 50-default.rules to allow adding more admin rules
  (jsc#PED-260, drop polkit-no-wheel-group.patch)

OBS-URL: https://build.opensuse.org/request/show/1112287
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=186
2023-09-19 15:44:51 +00:00
a372189673 Accepting request 1075307 from home:jsegitz:branches:Base:System
- Change permissions for rules folders (bsc#1209282)

OBS-URL: https://build.opensuse.org/request/show/1075307
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=184
2023-03-30 09:30:23 +00:00
ab9839a13e added polkit-actions-in-etc.patch
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=182
2022-11-09 16:18:51 +00:00
808d602907 Accepting request 1034870 from home:aschnell:branches:Base:System
- read actions also from /etc/polkit-1/actions (jsc#PED-1405)

OBS-URL: https://build.opensuse.org/request/show/1034870
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=181
2022-11-09 15:54:16 +00:00
c630e83434 - obsolete libpolkit0 also from baselibs.
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=179
2022-09-15 14:37:12 +00:00
a86140148b - obsolete libpolkit0 correctly, also do this for the baselibs.
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=178
2022-09-15 13:26:54 +00:00
67b6ed7232 Accepting request 997456 from home:luc14n0:branches:Base:System
Update to 121 stable release.

OBS-URL: https://build.opensuse.org/request/show/997456
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=176
2022-08-17 11:30:42 +00:00
b5ad31b2bc Accepting request 993691 from home:kukuk:branches:Base:System
- Use %_pam_vendordir

OBS-URL: https://build.opensuse.org/request/show/993691
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=174
2022-08-08 08:14:05 +00:00
577557153b Accepting request 992574 from home:msmeissn:branches:Base:System
- add split-provides for polkit:/usr/bin/pkexec. (bsc#1202070)

OBS-URL: https://build.opensuse.org/request/show/992574
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=172
2022-08-03 12:34:34 +00:00
70919da179 Accepting request 989830 from home:msmeissn:branches:Base:System
- split out pkexec into seperate package to make system hardening
  easier (to avoid installing it jsc#PED-132 jsc#PED-148).

OBS-URL: https://build.opensuse.org/request/show/989830
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=170
2022-07-18 09:49:15 +00:00
92d4914aa9 - Fixed denial of service via file descriptor leak (bsc#1195542 CVE-2021-4115)
0001-CVE-2021-4115-GHSL-2021-077-fix.patch

OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=169
2022-02-22 10:49:38 +00:00
0f67cffa04 Accepting request 949263 from home:favogt:dukkit
- Switch from mozjs to duktape:
  * Add duktape-support.patch

Provides the same features as with mozjs, but is *much* smaller both during
build and runtime. Before, installing polkit needed 62.0 MiB, with this it's
just 16.3 MiB. (Tested in an opensuse/tumbleweed container).

I didn't encounter any errors while playing around with it in a Live CD.

OBS-URL: https://build.opensuse.org/request/show/949263
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=168
2022-01-26 12:54:22 +00:00
dd1b57c1c4 - Fixed pkexec Local Privilege Escalation aka pwnkit (CVE-2021-4034 bsc#1194568)
CVE-2021-4034-pkexec-fix.patch

OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=167
2022-01-25 18:16:00 +00:00
0fb5828fa5 Accepting request 936022 from home:dirkmueller:Factory
- update to 0.120:
  * transition from Intltool to gettext
  * several tarball, meson and pipeline fixups
  * Portuguese translation
  * Romanian translation
  * meson build system added
  * CVE-2021-3560 mitigation
  * properties in text listener
  * typos fixups
  * Update Hungarian translation
- drop CVE-2021-3560.patch  (upstream)

OBS-URL: https://build.opensuse.org/request/show/936022
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=166
2021-12-07 10:14:49 +00:00
1cee8056d6 osc copypac from project:Base:System package:polkit revision:162
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=165
2021-12-06 13:57:16 +00:00
10f4e48b3c - update to 0.120:
* transition from Intltool to gettext
  * several tarball, meson and pipeline fixups
  * Portuguese translation
  * Romanian translation
  * meson build system added
  * CVE-2021-3560 mitigation
  * properties in text listener
  * typos fixups
  * Update Hungarian translation
- drop CVE-2021-3560.patch  (upstream)

OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=163
2021-12-06 10:30:34 +00:00
7b17a65c1e Accepting request 926568 from home:msmeissn:branches:Base:System
- fork libpolkit0 package into libpolkit-agent-1-0 and libpolkit-gobject-1-0
  as mandated. bsc#1191781

OBS-URL: https://build.opensuse.org/request/show/926568
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=162
2021-10-20 16:17:29 +00:00
11cc2a00ba Accepting request 906939 from home:gmbr3:Active
- Change to using systemd-sysusers
- Remove unneeded shadow dependency, no longer required due to
  systemd-sysusers
- Fix 50-default.rules file-parent-ownership-mismatch warning
- Remove --with-pic, no effect with --disable-static

OBS-URL: https://build.opensuse.org/request/show/906939
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=159
2021-07-19 06:47:41 +00:00
3729596378 Accepting request 904548 from home:schubi2
- Move /etc/polkit-1/rules.d/50-default.rules to
  /usr/share/polkit-1/rules.d/50-default.rules. The first location
  is only for admin changes.
- Fix verifyscript: the path to the binary was wrongly defined as
  %{_libexecdir}/lib.
- CVE-2021-3560: fixed a local privilege escalation using polkit_system_bus_name_get_creds_sync()
 (bsc#1186497)
  CVE-2021-3560.patch
- Move /etc/dbus-1/system.d to /usr/share/dbus-1/system.d, the
  first location is only for admin changes
- Move pam configuration to /usr/etc/pam.d
move to libexec dir is still not complete:
- add polkit-adjust-libexec-path.patch: There is another hard coded reference
  of lib/ in the code that this patch addresses.
- also adjust invocation of %set_permissions and %verify_permissions to new
  libexec dir location.
- also set libprivdir during build, otherwhise systemd and D-Bus service files
  contain the wrong path and we'll get runtime errors.
- Install private binaries into libexec instead of into lib. For this an
  override of the custom libprivdir variable is necessary, because upstream
  explicitly moved away from libexecdir via upstram commit
  6fbcc6cd839680fcefd81c4a43676e7c031c9859.
- Update to version 0.118:
  + Updated dependency to mozjs78.
  + Tarball fixes.
- Replace pkgconfig(mozjs-68) for pkgconfig(mozjs-78)
  BuildRequires following upstreams port.
- Update to version 0.117:
  + Activated Gitlab CI.
  + Updated dependency to mozjs68.
  + Memory management fixes.
  + Updated translations.
- Replace pkgconfig(mozjs-60) for pkgconfig(mozjs-68)
  BuildRequires following upstreams port.
- Fix usage of libexecdir instead of prefix/lib where applicable.
- polkit-keyinit.patch: add pam_keyinit to the polkit configuration (bsc#1144053)
- Update to version 0.116:
  + Leaking zombie child processes.
  + Possible resource leak found by static analyzer.
  + Output messages tuneup.
  + Sanity fixes.
  + pkttyagent tty echo disabled on SIGINT.
  + HACKING: add link to Code of Conduct.
  + polkitbackend: comment typos fix.
  + configure.ac: fix detection of systemd with cgroups v2.
  + CVE-2018-19788 High UIDs overflow fix.
  + CVE-2019-6133 Slowfork vulnerability fix.
  + Allow unset process-uid.
  + Port the JS authority to mozjs-60.
  + Use JS_EncodeStringToUTF8.
  + Updated translations.
- Replace pkgconfig(mozjs-52) with pkgconfig(mozjs-60)
  BuildRequires following upstreams changes.
- Drop patches fixed upstream:
  + polkit-fix-possible-resource-leak.patch
  + polkit-fix-leaking-zombie-child-processes.patch
  + polkit-CVE-2018-19788.patch
- Refresh patches with quilt.
- Use systemd_ordering instead of systemd_requires: strictly
  speaking, polkit does not require systemd to be present. Just
  that when we install on a system with systemd (e.g outside
  containers) we would want systemd to be present before
  installing polkit. Help also reduce a cycle without special hacks
  in systemd.spec.
- bsc#1130588: Require shadow instead of old pwdutils
- User proper Requires(pre)/Requires(post) for permissions and
  shadow
- polkit-CVE-2018-19788.patch: Fixed handling of UIDs over MAX_UINT
  (bsc#1118277 CVE-2018-19788)
- Add polkit-fix-possible-resource-leak.patch: Fix possible
  resource leak found by static analyzer.
- Add polkit-fix-leaking-zombie-child-processes.patch: polkitd: fix
  zombie not reaped when js spawned process timed out (fdo#106021).
- Update to version 0.115:
  - Fix CVE-2018-1116: Trusting client-supplied UID (bsc#1099031)
  - jsauthority: pass "%s" format string to remaining report function
    (obsoletes polkit-jsauthority-pass-format-string.patch)
- Update to version 0.114:
  + Port to mozjs 52, the latest version of the firefox JavaScript
    engine.
  + Add gettext support for policy files.
  + Fixes for various memory leaks.
  + Updated translations.
- Update keyring with Ray Strode <halfline@gmail.com> public key.
- Drop with_systemd define and all conditionals and
  polkit-no-systemd.patch and ConsoleKit BuildRequires, we only
  support systemd now.
- Drop upstream fixed polkit-itstools.patch.
- Rebase pkexec.patch with quilt.
- Add gcc-c++ and pkgconfig(mozjs-52) BuildRequires: New
  dependencies.
- Drop conditional pkgconfig(mozjs-17.0) and pkgconfig(mozjs185):
  no longer supported.
- Drop autoconf and automake BuildRequires: They are implicit via
  libtool BuildRequires.
- Replace glib2-devel and gobject-introspection-devel with their
  pkgconfig counterparts: pkgconfig(gio-unix-2.0),
  pkgconfig(gmodule-2.0) and pkgconfig(gobject-introspection-1.0).
- Add polkit-jsauthority-pass-format-string.patch: jsauthority:
  pass "%s" format string to remaining report function, patch from
  upstream git, adding missed commit (bgo#105865).
- Drop polkit-revert-session-magic.patch: Upstream systemd bug is
  since a long time fixed (gh#systemd#58) (boo#954139).
- pkexec.patch: pkexec: allow --version and --help even if not setuid
- Modernize spec-file by calling spec-cleaner
- Add polkit-itstools.patch: Add gettext support for .policy files.
- Use gettext as fallback to get potential distro translations for
  polkit actions. Similar mechnism as used for desktop file
  translations. That way it's possible to use weblate to add
  additional translations that are not provided by upstream
  (polkit-gettext.patch).
- Use pkgconfig() instead of requiring systemd package names directly.
- systemd.pc is shipped by systemd main package (bsc#983167)
  Strangely polkit wants systemd.pc to detect that the target system
  is running systemd even if its configured to build systemd support...
- polkit-revert-session-magic.patch: revert a session detection change
  that could lead to sessions not being detected as active due to 
  a systemd bug. bsc#954139
- Update to 0.113:
  * Fix CVE-2015-4625
  * Fix CVE-2015-3256
  * Fix CVE-2015-3255
  * Fix CVE-2015-3218
  * On systemd-213 and later, the “active” state is shared across
    all sessions of an user, instead of being tracked separately
  * pkexec: when not given a program to execute, runs the users’
    shell by default
- Remove polkit-no-kded-leak.patch (upstreamed)
- Try to fix kded leaking due to powerdevil exposing this issue in
  polkit: (bsc#912889)
  * polkit-no-kded-leak.patch
- Added gpg signature and keyring with David Zeuthen and Miloslav Trmac
  ids.
- Fixed URL
- Update to 0.112
  + polkitunixprocess: Deprecate racy APIs
  + pkcheck: Support --process=pid,start-time,uid syntax too
    (CVE-2013-4288)
  + Use GOnce for interface type registration
  + Add czech translation po file to distribution
  + Update the czech once more with newest pot file
- On openSUSE 13.1+, switch from mozjs185 to mozjs-17.0 by:
  + Conditionally BuildRequire pkgconfig(mozjs-17.0).
- Drop libmozjs185-1_0 Recommends: the library is actually required
  and auto-detected as such by rpm (from 0.111 changes: "The
  JavaScript interpreter is now mandatory").
- Update to 0.111
  + Both js185 and mozjs17 versions of SpiderMonkey are supported
  + The JavaScript interpreter is now mandatory
  + Fixed various memory leaks
  + Respect SUID_CFLAGS and SUID_LDFLAGS
  + Set process environment from pam_getenvlist()
  + Fix the build with automake 1.13
- Drop polkit-suid_flags.patch and automake-113.patch, those
  patches are included in this release
- Add automake-113.patch, fixes build with automake-1.13
- Recommend libmozjs185-1_0 which is dlopen'ed and required for JS
  rules
- Update to 0.110
  + Set XAUTHORITY environment variable if is unset
  + Use mutex and condition variables properly
  + Build fixes.
- Changes from version 0.109:
  + Include gmodule-2.0 to avoid linker errors
  + Don't require libmozjs185 devel packages for polkit rules
    to work
- Drop polkit-link-gmodule.patch and polkit-libmozjs.patch, those
  are merged upstream
- Only mark the following files as %config, not %config(noreplace):
  + %{_sysconfdir}/dbus-1/system.d/org.freedesktop.PolicyKit1.conf
  + %{_sysconfdir}/pam.d/polkit-1
  + %{_sysconfdir}/polkit-1/rules.d/50-default.rules
  PolicyKit's own config files should only be changed for good reason
  and we want to prefer openSUSE's defaults (you still get an .rpmsafe
  file)
- Add polkit-libmozjs.patch: dlopen libmozjs185.so.1.0 instead of
  libmozjs185.so, which is packaged in the -devel package
  (bnc#793562)
- Update to version 0.108:
  + PolkitAgent: Avoid crashing if initializing the server object
    fails
  + Fall back to authenticating as uid 0 if the list of admin
    identities is empty
  + Dynamically load libmozjs185.so and cope with it not being
    available
  + docs: mention the audience for authorization rules
  + build: Fix .gir generation for parallel make
- Only conditionally Require ConsoleKit when with_systemd is 0:
  systemd support obsoletes ConsoleKit.
- Add polkit-link-gmodule.patch: Link against gmodule-2.0.
- Change libpolkit0 to require polkit >= %version instead of the
  exact version. This will ease upgrade problems should there ever
  be a soname bump of libpolkit0.
- Enable systemd inetegration (change with_systemd to 1): As an
  agreed target for 12.3, systemd integration will be enabled.
- Add pwdutils to prereq for groupadd and useradd.
- Add polkit-no-systemd.patch: this patch, only applied when not
  building systemd support, removes the systemd service reference
  from the dbus .service file. This is needed as the systemd
  .service file does not get installed in that case and dbus gets
  confused because it expects it.
- Make %{_datadir}/polkit-1/rules.d and
  %{_sysconfdir}/polkit-1/rules.d owned by user polkitd, as those
  directories have 0700 as permissions.
- Those two changes should fix polkit so it can start.
  Fix bnc#782395.
- Use %{_localstatedir}/lib/polkit for $HOME of polkit user,
  instead of %{_libexecdir}/polkit-1. The directory is manually
  created in %install.
- Update to version 0.107:
  + Try harder to look up the right localization
  + Introduce a polkit.Result enumeration for authorization rules
  + pkexec: add support for argv1 annotation and mention
    shebang-wrappers
  + doc: update guidance on situations where there is no polkit
    authority
- Changes from version 0.106:
  + Major change: switch from .pkla files (keyfile-format) to
    .rules files (JavaScript)
  + Nuke polkitbackend library, localauthority backend and
    extension system
  + Run polkitd as an unprivileged user
  + Add a systemd .service file
  + Several other code changes.
  + Updated documentation.
- Changes from version 0.105:
  + Add pkttyagent(1) helper
  + Make it possible to influence agent registration with an a{sv}
    parameter
  + Several other code changes.
- Add pkgconfig(mozjs185) BuildRequires: new dependency for the
  authority backend.
- Rebase polkit-no-wheel-group.patch: the admin configuration is
  now in a .rules file.
- Rebase polkit-suid_flags.patch.
- Explicitly pass --enable-libsystemd-login or
  --disable-libsystemd-login, depending on whether we build systemd
  support.
- Add a %pre script to create the polkitd group and user, as
  polkitd now run as an unprivileged user.
- also use -z now for binary hardening
- Package /etc/polkit-1/localauthority and its subdirectories. They
  were forgotten because they were empty, but people might need
  them to put .pkla files.
- Change the way we pass -fpie/-pie:
  + Drop polkit-pie.patch: this was not upstreamable.
  + Add polkit-suid_flags.patch: respect SUID_CFLAGS/SUID_LDFLAGS
    when building the suid binaries (pkexec and
    polkit-agent-helper-1).
  + Add autoconf, automake and libtool BuildRequires, and call
    autoreconf, for the new patch.
  + Set SUID_CFLAGS to -fPIE and SUID_LDFLAGS to -pie in %build.
  + Pass --with-pic to configure instead of changing CFLAGS to
    contain -fPIC.
- fixed bnc#743145 - added -fpie/-pie flags to compilation and linking of polkit-agent-helper and pkexec
- Split typelib file into typelib-1_0-Polkit-1_0 subpackage.
- Add typelib-1_0-Polkit-1_0 Requires to devel subpackage.
- Add explicit libpolkit0 Requires to devel subpackage: it was
  missing before.
- Remove explicit glib2-devel Requires from devel subpackage: it
  will automatically be added the pkgconfig() way.
- Improve summary of libpolkit0 subpackage.
- A quick test reveals that the systemd backend does not 
  integrate very well with packages yet, revert.
- Previous update missed systemd-devel in buildrequires 
  without it no systemd support is built
- Update to version 0.104:
  + Add optional systemd support
  + Add netgroup support (fdo#43610)
  + Add unit tests (fdo#43608)
- Changes from version 0.103:
  + Mistype in DBus object: PoliycKit1 -> PolicyKit1
  + Add support for the org.freedesktop.policykit.imply annotation
  + Add --no-debug option and use this for D-Bus activation
  + Add org.freedesktop.policykit.owner annotation (fdo#41025)
  + Default to AdminIdentities=unix-group:wheel for local authority
- Drop patches that were taken from upstream:
  + 0001-Add-support-for-the-org.freedesktop.policykit.imply-a.diff
  + 0002-Add-no-debug-option-and-use-this-for-D-Bus-activation.diff
  + 0003-Bug-41025-Add-org.freedesktop.policykit.owner-annotat.diff
- Add polkit-no-wheel-group.patch: do not allow the wheel group as
  admin identity, and revert to only accept the root user for this.
- pick some patches from git to add support for
  org.freedesktop.policykit.imply, disable debug spam and allow
  unprivileged users to query authorizations (bnc#698250)
- Update to version 0.102:
  + pkexec:
    - fdo#38769: Support running X11 apps
    - Avoid time-of-check-to-time-of-use problems with parent
      process
  + Fix backend crash if a .policy file does not specify <message>
  + Fix multi-line pam prompt handling
  + Don't show diagnostic messages intended for the administrator
    to the end user
  + PolkitUnixProcess:
    - Clarify that the real uid is returned, not the effective one
    - Record the uid of the process
  + Backend: Use polkit_unix_process_get_uid() to get the owner of
    a process
  + Introspection fixes:
    - Add --c-include to the gir files
    - Specify exported pkg-config files in GIRs
  + Build fix.
- Drop polkit-CVE-2011-1485-1.patch, polkit-CVE-2011-1485-2.patch,
  polkit-CVE-2011-1485-3.patch, polkit-CVE-2011-1485-4.patch: fixed
  upstream.
- Remove service usage, following the new consensus on Factory
  packaging.
- BuildIgnore ruby, which is being dragged in via indirect
  dependencies by gtk-doc for one of the helpers, which we do not
  need during the build of polkit. Not dragging ruby in resolves a
  build-cycle.
- Use %set_permissions instead of deprecated %run_permissions in
  %post.
- Add permissions PreReq, which was missing before.
- use LGPLv2.1+ in spec file
- stat race condition (CVE-2011-1485) (bnc#688788)
- Remove PolkitAgent-1.0.typelib from main package, it is in
  library package.
- update to 0.101: 
  * tons of bug fixes, see NEWS
- fix file list
- Update to version 0.99:
  + Remove duplicate definitions of enumeration types
  + Fix (correct) GCC warning about possibly-uninitialized variable
  + Fix another GCC uninitialized variable warning
  + fdo#29816: Install polkitagentenumtypes.h
- Drop polkit-install-missing-header.patch: fixed upstream.
- Update to version 0.98:
  + Fix scanning of unix-process subjects
  + Add textual authentication agent and use it in pkexec(1)
  + Fix ConsoleKit interaction bug
  + pkexec: add --disable-internal-agent option
  + pkcheck: add --enable-internal-agent option
  + Fix wording in pkexec(1) man page
  + Various doc cleanups
- Changes from version 0.97:
  + Port to GDBus
  + Add shadow authentication support
  + Remove Lock Down functionality
  + fdo#26982: pkexec information disclosure vulnerability
  + Make polkitd accept --replace and gracefully handle SIGINT
  + Implement polkit_temporary_authorization_new_for_gvariant()
  + Make NameOwnerChanged a private impl detail of the interactive
    authority
  + Add a GPermission implementation
  + PolkitAuthority: Implement failable initialization
  + PolkitAuthority: Add g_return_if_fail() checks
  + Add g_return_if_fail() to all public API entry points
  + Use polkit_authority_get_sync() instead of deprecated
    polkit_authority_get
  + PolkitBackend: Don't export unneeded convenience API
  + Update GI annotations
  + Don't dist org.freedesktop.ConsoleKit.xml.
  + Properly reference headers
  + fdo#29051: Configuration reload on every query
- Drop pkexec-information-disclosure.patch: fixed upstream.
- Add polkit-install-missing-header.patch to install a header that
  should get installed.
- Remove eggdbus-devel BuildRequires.
- Build with introspection support: add gobject-introspection
  BuildRequires and pass --enable-introspection to configure.
- Fix groups of all packages to be valid groups.
- use %_smp_mflags
- fix pkexec information disclosure
  (fdo#26982, CVE-2010-0750, bnc#593959)
- add baselibs.conf
- new upstream release 0.96
  - Bug 25367 — Also read local authority configuration data from /etc
  - Run the open_session part of the PAM stack in pkexec(1)
  - Bug 25594 – System logging
  - Properly handle return value from getpwnam_r()
  - Fix error message when no authentication agent is available
  - Make pkexec(1) validate environment variables
  - Make pkexec(1) use the syslogging facilities
  - Save original cwd in pkexec(1) since it will change during the life-time
  - Complain on stderr, not stdout
  - Don't log authorization checks
- update to 0.95:
 The major change this release is that the lockdown feature has
 been cleaned up in a way so it isn't specific to the local
 authority. See the NEWS files for more details.
- Package documentation as noarch
- Add Requires on polkit to libpolkit0: all applications using
  libpolkit0 will really need polkit to be installed to work
  properly.
- new upstream release 0.94
  - Allow unprivileged callers to check authorizations
  - Don't spawn man(1) from a setuid program
  - Add polkit.retains_authorization_after_challenge to authz result
  - Ensure all fds except stdin/stdout/stderr are closed after exec(2)
  - Be more careful when determining process start time
  - Remove temporary authorization when the subject it applies to vanishes
  - Generate GI gir and typelibs for libpolkit-gobject-1
- drop patches which are in the release now
- disable introspection
- add upstream patches:
   polkit-close-stdfds.patch
   polkit-no-man-spawn.patch
   polkit-proc-stat-parse-fix.patch 
- drop rpmlint patch
- check for the right binary in verify_permisisons
- disable suid bit for now to get software build on top
- split out libraries to follow shared library policy
- update to version 0.93
- initial import of polkit 0.92

OBS-URL: https://build.opensuse.org/request/show/904548
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=158
2021-07-08 14:26:50 +00:00
1ba813a495 - CVE-2021-3560: fixed a local privilege escalation using polkit_system_bus_name_get_creds_sync()
(bsc#1186497)
  CVE-2021-3560.patch

OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=156
2021-06-11 09:24:05 +00:00
9769998cf8 osc copypac from project:Base:System package:polkit revision:149, using keep-link
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=155
2021-06-11 09:21:57 +00:00
8b1e36f21f - polkit 0.119.
Highlights:
  - meson build system added
  - CVE-2021-3560 mitigation (bsc#1186497)
  - properties in text listener

OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=150
2021-06-11 07:23:39 +00:00
637952ed0f Accepting request 898646 from home:dimstar:Factory
- Fix verifyscript: the path to the binary was wrongly defined as
  %{_libexecdir}/lib.

OBS-URL: https://build.opensuse.org/request/show/898646
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=149
2021-06-09 07:12:21 +00:00
0af61cfa2f Accepting request 878406 from home:kukuk:branches:Base:System
- Move /etc/dbus-1/system.d to /usr/share/dbus-1/system.d, the
  first location is only for admin changes
- Move pam configuration to /usr/etc/pam.d

OBS-URL: https://build.opensuse.org/request/show/878406
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=148
2021-03-15 12:53:01 +00:00
cc6ffe8a13 Accepting request 860113 from home:mgerstner:branches:Base:System
move to libexec dir is still not complete:
- add polkit-adjust-libexec-path.patch: There is another hard coded reference
  of lib/ in the code that this patch addresses.
- also adjust invocation of %set_permissions and %verify_permissions to new
  libexec dir location.

OBS-URL: https://build.opensuse.org/request/show/860113
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=147
2021-01-04 10:16:58 +00:00
27bf312619 Accepting request 859146 from home:mgerstner:branches:Base:System
- also set libprivdir during build, otherwhise systemd and D-Bus service files
  contain the wrong path and we'll get runtime errors.

OBS-URL: https://build.opensuse.org/request/show/859146
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=144
2020-12-29 09:02:16 +00:00
2d2f6bb12f Accepting request 859031 from home:mgerstner:branches:Base:System
- Install private binaries into libexec instead of into lib. For this an
  override of the custom libprivdir variable is necessary, because upstream
  explicitly moved away from libexecdir via upstram commit
  6fbcc6cd839680fcefd81c4a43676e7c031c9859.

OBS-URL: https://build.opensuse.org/request/show/859031
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=143
2020-12-29 07:54:33 +00:00
906b255a1b Accepting request 843557 from home:iznogood:branches:Base:System
- Update to version 0.118:
  + Updated dependency to mozjs78.
  + Tarball fixes.
- Replace pkgconfig(mozjs-68) for pkgconfig(mozjs-78)
  BuildRequires following upstreams port.

OBS-URL: https://build.opensuse.org/request/show/843557
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=141
2020-10-27 09:39:20 +00:00
da7f74ee24 Accepting request 823732 from home:iznogood:branches:Base:System
New upstream release

OBS-URL: https://build.opensuse.org/request/show/823732
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=139
2020-07-31 12:03:13 +00:00
6603045213 Accepting request 752325 from home:iznogood:branches:Base:System
- Fix usage of libexecdir instead of prefix/lib where applicable.

OBS-URL: https://build.opensuse.org/request/show/752325
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=137
2019-12-05 09:19:13 +00:00
7039ba5030 Accepting request 736147 from home:msmeissn:branches:Base:System
- polkit-keyinit.patch: add pam_keyinit to the polkit configuration (bsc#1144053)

OBS-URL: https://build.opensuse.org/request/show/736147
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=135
2019-10-08 12:46:03 +00:00
c86a2868e2 Accepting request 706749 from home:iznogood:branches:Base:System
New upstream release .

NOTE! -- Do not ack this until mozjs60 sub https://build.opensuse.org/request/show/706263 is acked into Factory -- Needs this change to build OK.

OBS-URL: https://build.opensuse.org/request/show/706749
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=133
2019-06-13 19:54:52 +00:00
c6e674bb1e Accepting request 702025 from home:dimstar:Factory
- Use systemd_ordering instead of systemd_requires: strictly
  speaking, polkit does not require systemd to be present. Just
  that when we install on a system with systemd (e.g outside
  containers) we would want systemd to be present before
  installing polkit. Help also reduce a cycle without special hacks
  in systemd.spec.

OBS-URL: https://build.opensuse.org/request/show/702025
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=131
2019-05-10 14:54:03 +00:00
4f67e78214 Accepting request 698177 from home:jubalh:branches:Base:System
- bsc#1130588: Require shadow instead of old pwdutils
- User proper Requires(pre)/Requires(post) for permissions and
  shadow

OBS-URL: https://build.opensuse.org/request/show/698177
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=129
2019-04-26 12:35:25 +00:00
bbfd4e1577 Accepting request 660356 from home:msmeissn:branches:Base:System
- polkit-CVE-2018-19788.patch: Fixed handling of UIDs over MAX_UINT
  (bsc#1118277 CVE-2018-19788)

OBS-URL: https://build.opensuse.org/request/show/660356
OBS-URL: https://build.opensuse.org/package/show/Base:System/polkit?expand=0&rev=127
2018-12-20 18:04:49 +00:00