78948b7b6e
Accepting request 1325956 from home:msmeissn:branches:Base:System
Marcus Meissner2026-01-08 12:49:43 +00:00
e6e1be1f23
- Updated to version 127: - socket-activated polkit-agent-helper can now run without SETUID (Luca Boccassi) - user id (UID) now accessible to JavaScript rules via subject.uid (Rosentti, Jan Rybar) - INI config file support for polkitd with configurable auth expiration timer (Luca Boccassi) - auth_keep: skip re-authentication if new process shares same UID/parent/cgroup/tty (Luca Boccassi) - CheckAuthorization now returns 'polkit.result' in the details dict (Luca Boccassi) - pkexec: set $SUDO_UID/$SUDO_GID for compatibility with sudo (Lennart Poettering) - pkexec: use realpath when comparing org.freedesktop.policykit.exec.path (Walter Doekes) - memory limits added to systemd unit to mitigate memory leaks (Alexander Meshcheryakov) - new translations: Bulgarian (twlvnn kraftwerk), Occitan (Mejans) - systemd-socket-activation.patch: upstream, removed - auth_keep.patch: upstream, removed - sudo_uid.patch: upstream, removed - added polkitd.conf.5 manpage, added polkitd.conf
Marcus Meissner2026-01-08 12:49:43 +00:00
46f4452900
Accepting request 1315270 from Base:System
Ana Guerrero2025-11-05 15:17:56 +00:00
dd8153cbe9
Accepting request 1315270 from Base:System
Ana Guerrero2025-11-05 15:17:56 +00:00
8a41cf2b0d
Accepting request 1315266 from home:kukuk:pwaccess
Marcus Meissner2025-11-03 10:39:07 +00:00
5bed8ba216
- Backport for NoNewPrivs support: - systemd-socket-activation.patch: start agent via socket, no setuid - Backport of patches for better run0 usability: - auth_keep.patch: do not ask for reauth if new process shares same UID/parent/cgroup/tty - sudo_uid.patch: also set $SUDO_UID/$SUDO_GID for compat with sudo
Marcus Meissner2025-11-03 10:39:07 +00:00
77d6ab0c65
Accepting request 1305233 from Base:System
Ana Guerrero2025-09-17 14:43:09 +00:00
05942ccbdf
Accepting request 1305233 from Base:System
Ana Guerrero2025-09-17 14:43:09 +00:00
31741dfaa4
Accepting request 1305226 from home:Andreas_Schwab:Factory
Marcus Meissner2025-09-16 15:36:12 +00:00
74a78b2a85
Accepting request 1303228 from home:msmeissn:branches:Base:System
Marcus Meissner2025-09-08 14:36:47 +00:00
9f2eb8ecb4
- revert upstream change to have /etc/polkit-1/rules.d as tempdir
Marcus Meissner2025-09-08 14:36:47 +00:00
5e9987fd46
Accepting request 1302995 from home:msmeissn:branches:Base:System
Marcus Meissner2025-09-06 08:47:20 +00:00
7889fda875
- store our defaults in /usr/share/ as /etc/polkit is now a tempdir
Marcus Meissner2025-09-06 08:47:20 +00:00
29c7235525
Accepting request 1302945 from home:msmeissn:branches:Base:System
Marcus Meissner2025-09-05 15:12:14 +00:00
78b8bd4db1
- Updated to version 126: + Highlights: - many code fixes detected either by CI or the author himself (Frantisek Sumsal) - shellcheck and dependabot integration (Jan Macku) - search for rules in /usr/local/share rather than /usr/local/lib (Luca Boccassi) - Implement LogControl1 protocol for dynamic log level changes (Luca Boccassi) - read actions also from /etc/, /run/ and /usr/local/share/ (Luca Boccassi) - mozjs dropped in favor of duktape (Xi Ruoyao) - many other fixes in build system and polkit code (Many thanks to all the authors.) - Updated to version 125: + Highlights: - introduction of CodeQL and a new integration test suite (Frantisek Sumsal) - dropped mocklibc (Frantisek Sumsal) - syslog-style log-levels introduction (Jan Rybar) - LogControl integration (Luca Boccassi) - pkexec: "No session for cookie" finally fixed (huxiaodong) - resources optimizations: only instances affected by sessions-change recalculate authorizations (Jan Rybar, thanks to Michal Sekletar and Milan Crha) - meson tweaks (Alyssa Ross, Luca Boccassi, Michael Biebl, Michael Olbrich) - build warnings cleanup (peelz) - Packit service configuration for the new upstream platform (Vincent Mihalkovic) - systemd-tmpfiles.d integration (Vincent Mihalkovic) - other fixes and changes (Gleb Popov, heather7283, Tianyu Chen, Tobias Stoeckmann) - internationalization: Slovenian (filmsi), Hindi (Scrambled777) - Updated to version 124: + Highlights: - PIDFDs are used if available to track processes - pidfd parameter available for CheckAuthorization() - systemd-sysuser enabled for polkit - polkit-actions-in-etc.patch: done upstream in commit 9958c259f82b066f613d171d2934c1bd829e31a4 - polkit-fix-implicit.patch: not needed anymore
Marcus Meissner2025-09-05 15:12:14 +00:00
f31b7b30bd
Accepting request 1193874 from home:dimstar:Factory
Bjørn Lie2024-08-14 12:50:59 +00:00
600cfd932c
- BuildRequire gettext-devel instead of gettext: Allows OBS to shortcut throught gettext-runtime-mini.
Bjørn Lie2024-08-14 12:50:59 +00:00
b9a37eb73e
Accepting request 1187081 from Base:System
Ana Guerrero2024-07-14 06:48:49 +00:00
6fa4c52e4d
Accepting request 1187081 from Base:System
Ana Guerrero2024-07-14 06:48:49 +00:00
eca3cbd3a7
Accepting request 1187079 from home:jamborm:gcc14fixes
Marcus Meissner2024-07-12 13:08:58 +00:00
8e31deb180
- Add -Wno-error=implicit-function-declaration to %optflags to work-around an issue in mocklibc (which has been meanwhile removed by upstream) with exactly this kind of issue.
Marcus Meissner2024-07-12 13:08:58 +00:00
92d4914aa9
- Fixed denial of service via file descriptor leak (bsc#1195542 CVE-2021-4115) 0001-CVE-2021-4115-GHSL-2021-077-fix.patch
Marcus Meissner2022-02-22 10:49:38 +00:00
5bfc2cd366
- Fixed denial of service via file descriptor leak (bsc#1195542 CVE-2021-4115) 0001-CVE-2021-4115-GHSL-2021-077-fix.patch
Marcus Meissner2022-02-22 10:49:38 +00:00