pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

pkg/60823: pkgsrc: security/polkit does not build on DragonFly and OpenBSD



>Number:         60823
>Category:       pkg
>Synopsis:       pkgsrc: security/polkit does not build on DragonFly and OpenBSD
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Tue Sep 29 18:20:00 +0000 2026
>Originator:     Showta Ishizaki
>Release:        pkgsrc as of 2026-09-30, security/polkit at polkit-127nb4
>Organization:
>Environment:
System: DragonFly 6.4.2 x86_64
>Description:
	polkit-127 defines SO_PEERPIDFD itself when the system does not,
	with no platform test, so the socket-activation block in
	src/polkitagent/polkitagenthelper-pam.c is compiled everywhere.
	Inside it errno is compared against ENODATA, which FreeBSD,
	DragonFly and OpenBSD do not have.

	The Makefile now works around this for FreeBSD with
	CPPFLAGS.FreeBSD+=-DENODATA=ENOATTR, which leaves DragonFly and
	OpenBSD as they were.  Upstream fixed it at the source after 127:

	  066b55bf2e2b  polkitagenthelper-pam.c: ifdef out the socket
	                activation functionality
	  72c28782b17e  Fix build on systems without SO_PEERCRED.

	The second is what the tree's patch already carries for NetBSD.
	The first makes the SO_PEERPIDFD fallback Linux-only and wraps the
	block in #ifdef SO_PEERPIDFD, so none of the BSDs compile it and
	the ENODATA workaround is no longer needed.

	Separately, the CVE-2025-7519 entry in pkg-vulnerabilities has no
	upper bound (polkit-[0-9]*), so polkit-127 audits as vulnerable.
	The fix is upstream commit 107d3801361b, which is in 127 and not
	in 126, and its guard is in the distfile distinfo records.

>How-To-Repeat:
	Build security/polkit on DragonFly.

>Fix:
	The diff below replaces the patch with both upstream commits,
	applied to the pristine 127 source and the result diffed, drops
	the FreeBSD CPPFLAGS line, and bumps PKGREVISION because the
	socket-activation block is no longer compiled on NetBSD either.
	It also gives the CVE-2025-7519 entry the bound polkit<127;
	pkg_admin pmatch matches it against polkit-126 and not against
	polkit-127 or polkit-127nb5.

	With it, security/polkit builds and installs on DragonFly 6.4.2,
	FreeBSD 14.4 and NetBSD 11.0 amd64.  On OpenBSD the build stops
	earlier, in devel/meson, so I could not see polkit itself build
	there.

	Diff against pkgsrc-current of 2026-09-30:

	Index: doc/pkg-vulnerabilities
	--- doc/pkg-vulnerabilities	2026-09-30 03:17:12
	+++ doc/pkg-vulnerabilities	2026-09-30 03:17:29
	@@ -27201,7 +27201,7 @@
	 php82-soap<8.2.29	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6491
	 php83-soap<8.3.23	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6491
	 php84-soap<8.4.10	denial-of-service	https://nvd.nist.gov/vuln/detail/CVE-2025-6491
	-polkit-[0-9]*		out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2025-7519
	+polkit<127		out-of-bounds-write	https://nvd.nist.gov/vuln/detail/CVE-2025-7519
	 py{27,39,310,311,312,313}-aiohttp<3.12.14	request-smuggling	https://nvd.nist.gov/vuln/detail/CVE-2025-53643
	 roundup<2.5.0		cross-site-scripting	https://nvd.nist.gov/vuln/detail/CVE-2025-53865
	 p5-Plack-Middleware-Session<0.35		insufficiently-random-numbers	https://nvd.nist.gov/vuln/detail/CVE-2025-40923
	Index: security/polkit/Makefile
	--- security/polkit/Makefile	2026-09-30 03:17:11
	+++ security/polkit/Makefile	2026-09-30 03:17:29
	@@ -1,7 +1,7 @@
	 # $NetBSD: Makefile,v 1.65 2026/09/29 06:07:25 wiz Exp $
	 
	 DISTNAME=	polkit-127
	-PKGREVISION=	4
	+PKGREVISION=	5
	 CATEGORIES=	security
	 MASTER_SITES=	${MASTER_SITE_GITHUB:=polkit-org/}
	 
	@@ -32,9 +32,6 @@
	 BUILDLINK_TRANSFORM.SunOS+=	rm:-Wl,--as-needed
	 CPPFLAGS.SunOS+=		-D_POSIX_PTHREAD_SEMANTICS -D__EXTENSIONS__
	 LDFLAGS.SunOS+=			-lsocket
	-
	-# FreeBSD does not have ENODATA.
	-CPPFLAGS.FreeBSD+=		-DENODATA=ENOATTR
	 
	 .include "../../mk/bsd.prefs.mk"
	 
	Index: security/polkit/distinfo
	--- security/polkit/distinfo	2026-09-30 03:17:11
	+++ security/polkit/distinfo	2026-09-30 03:17:29
	@@ -4,7 +4,7 @@
	 SHA512 (polkit-127.tar.gz) = 54b315f2ca05e957e7b9aafda16c1cddcc2266d6018c77dbf4cfe73b7d5b1569e6e07570884b9c5ecc4bdb3a29966169006aa727b089019d959208f2b53067e6
	 Size (polkit-127.tar.gz) = 472872 bytes
	 SHA1 (patch-src_polkit_polkitunixprocess.c) = b95f8e5d7c1dd0ab9b084e3bd5b1fc6d05744b57
	-SHA1 (patch-src_polkitagent_polkitagenthelper-pam.c) = 74e3a9d1b3f4c4e28a2353f4f824c83c0032b97d
	+SHA1 (patch-src_polkitagent_polkitagenthelper-pam.c) = 492baae7c3942765db2d7f89346386435671c280
	 SHA1 (patch-src_polkitbackend_polkitbackendduktapeauthority.c) = 5e48729c3414ccd41faa2e60bf3c915207e21cd1
	 SHA1 (patch-src_polkitbackend_polkitd.c) = e587e99017128477522050391c5410024a1e25c7
	 SHA1 (patch-src_programs_pkttyagent.c) = d9044bcc2ebd79a885c7bbc8327bdebab5680748
	Index: security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c
	--- security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c	2026-09-30 03:17:11
	+++ security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c	2026-09-30 03:17:29
	@@ -1,11 +1,38 @@
	 $NetBSD: patch-src_polkitagent_polkitagenthelper-pam.c,v 1.1 2025/12/21 15:44:05 wiz Exp $
	 
	-Fix build on NetBSD.
	-https://github.com/polkit-org/polkit/pull/624
	+Fix build where ENODATA is missing (FreeBSD, DragonFly, OpenBSD), and
	+keep the NetBSD fix.
	 
	---- src/polkitagent/polkitagenthelper-pam.c.orig	2025-12-21 14:47:56.694667615 +0000
	+polkit defines SO_PEERPIDFD itself when the system does not, with no
	+platform test, so the socket-activation block is compiled everywhere,
	+and inside it errno is compared against ENODATA.  Two upstream commits,
	+both after polkit 127, fix this:
	+
	+  066b55bf2e2b  polkitagenthelper-pam.c: ifdef out the socket activation
	+                functionality
	+  72c28782b17e  Fix build on systems without SO_PEERCRED.
	+
	+The first makes the fallback define Linux-only and wraps the block in
	+#ifdef SO_PEERPIDFD; the second is the NetBSD fix this patch carried
	+before.  Remove when updating past 127.
	+
	+--- src/polkitagent/polkitagenthelper-pam.c.orig
	 +++ src/polkitagent/polkitagenthelper-pam.c
	-@@ -141,7 +141,9 @@ main (int argc, char *argv[])
	+@@ -38,7 +38,7 @@
	+ #    define SO_PEERPIDFD 0x404B
	+ #  elif defined(__sparc__)
	+ #    define SO_PEERPIDFD 0x0056
	+-#  else
	++#  elif defined(__linux__)
	+ #    define SO_PEERPIDFD 77
	+ #  endif
	+ #endif
	+@@ -137,11 +137,14 @@
	+       goto error;
	+     }
	+ 
	++#ifdef SO_PEERPIDFD
	+   /* We are socket activated and the socket has been set up as stdio/stdout, read user from it */
	    if (argv[1] != NULL && strcmp (argv[1], "--socket-activated") == 0)
	      {
	        socklen_t socklen = sizeof(int);
	@@ -15,7 +42,7 @@
	  
	        user_to_auth_free = read_cookie (argc, argv);
	        if (!user_to_auth_free)
	-@@ -165,8 +167,12 @@ main (int argc, char *argv[])
	+@@ -165,8 +168,12 @@
	            goto error;
	          }
	  
	@@ -28,7 +55,7 @@
	        if (rc < 0)
	          {
	            syslog (LOG_ERR, "Unable to get credentials from socket");
	-@@ -174,7 +180,9 @@ main (int argc, char *argv[])
	+@@ -174,9 +181,12 @@
	            goto error;
	          }
	  
	@@ -37,4 +64,7 @@
	 +#endif
	      }
	    else
	++#endif
	      user_to_auth = argv[1];
	+ 
	+   cookie = read_cookie (argc, argv);




Home | Main Index | Thread Index | Old Index