pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
pkg/60823: pkgsrc: security/polkit does not build on DragonFly and OpenBSD
>Number: 60823
>Category: pkg
>Synopsis: pkgsrc: security/polkit does not build on DragonFly and OpenBSD
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: pkg-manager
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Tue Sep 29 18:20:00 +0000 2026
>Originator: Showta Ishizaki
>Release: pkgsrc as of 2026-09-30, security/polkit at polkit-127nb4
>Organization:
>Environment:
System: DragonFly 6.4.2 x86_64
>Description:
polkit-127 defines SO_PEERPIDFD itself when the system does not,
with no platform test, so the socket-activation block in
src/polkitagent/polkitagenthelper-pam.c is compiled everywhere.
Inside it errno is compared against ENODATA, which FreeBSD,
DragonFly and OpenBSD do not have.
The Makefile now works around this for FreeBSD with
CPPFLAGS.FreeBSD+=-DENODATA=ENOATTR, which leaves DragonFly and
OpenBSD as they were. Upstream fixed it at the source after 127:
066b55bf2e2b polkitagenthelper-pam.c: ifdef out the socket
activation functionality
72c28782b17e Fix build on systems without SO_PEERCRED.
The second is what the tree's patch already carries for NetBSD.
The first makes the SO_PEERPIDFD fallback Linux-only and wraps the
block in #ifdef SO_PEERPIDFD, so none of the BSDs compile it and
the ENODATA workaround is no longer needed.
Separately, the CVE-2025-7519 entry in pkg-vulnerabilities has no
upper bound (polkit-[0-9]*), so polkit-127 audits as vulnerable.
The fix is upstream commit 107d3801361b, which is in 127 and not
in 126, and its guard is in the distfile distinfo records.
>How-To-Repeat:
Build security/polkit on DragonFly.
>Fix:
The diff below replaces the patch with both upstream commits,
applied to the pristine 127 source and the result diffed, drops
the FreeBSD CPPFLAGS line, and bumps PKGREVISION because the
socket-activation block is no longer compiled on NetBSD either.
It also gives the CVE-2025-7519 entry the bound polkit<127;
pkg_admin pmatch matches it against polkit-126 and not against
polkit-127 or polkit-127nb5.
With it, security/polkit builds and installs on DragonFly 6.4.2,
FreeBSD 14.4 and NetBSD 11.0 amd64. On OpenBSD the build stops
earlier, in devel/meson, so I could not see polkit itself build
there.
Diff against pkgsrc-current of 2026-09-30:
Index: doc/pkg-vulnerabilities
--- doc/pkg-vulnerabilities 2026-09-30 03:17:12
+++ doc/pkg-vulnerabilities 2026-09-30 03:17:29
@@ -27201,7 +27201,7 @@
php82-soap<8.2.29 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-6491
php83-soap<8.3.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-6491
php84-soap<8.4.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-6491
-polkit-[0-9]* out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2025-7519
+polkit<127 out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2025-7519
py{27,39,310,311,312,313}-aiohttp<3.12.14 request-smuggling https://nvd.nist.gov/vuln/detail/CVE-2025-53643
roundup<2.5.0 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-53865
p5-Plack-Middleware-Session<0.35 insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2025-40923
Index: security/polkit/Makefile
--- security/polkit/Makefile 2026-09-30 03:17:11
+++ security/polkit/Makefile 2026-09-30 03:17:29
@@ -1,7 +1,7 @@
# $NetBSD: Makefile,v 1.65 2026/09/29 06:07:25 wiz Exp $
DISTNAME= polkit-127
-PKGREVISION= 4
+PKGREVISION= 5
CATEGORIES= security
MASTER_SITES= ${MASTER_SITE_GITHUB:=polkit-org/}
@@ -32,9 +32,6 @@
BUILDLINK_TRANSFORM.SunOS+= rm:-Wl,--as-needed
CPPFLAGS.SunOS+= -D_POSIX_PTHREAD_SEMANTICS -D__EXTENSIONS__
LDFLAGS.SunOS+= -lsocket
-
-# FreeBSD does not have ENODATA.
-CPPFLAGS.FreeBSD+= -DENODATA=ENOATTR
.include "../../mk/bsd.prefs.mk"
Index: security/polkit/distinfo
--- security/polkit/distinfo 2026-09-30 03:17:11
+++ security/polkit/distinfo 2026-09-30 03:17:29
@@ -4,7 +4,7 @@
SHA512 (polkit-127.tar.gz) = 54b315f2ca05e957e7b9aafda16c1cddcc2266d6018c77dbf4cfe73b7d5b1569e6e07570884b9c5ecc4bdb3a29966169006aa727b089019d959208f2b53067e6
Size (polkit-127.tar.gz) = 472872 bytes
SHA1 (patch-src_polkit_polkitunixprocess.c) = b95f8e5d7c1dd0ab9b084e3bd5b1fc6d05744b57
-SHA1 (patch-src_polkitagent_polkitagenthelper-pam.c) = 74e3a9d1b3f4c4e28a2353f4f824c83c0032b97d
+SHA1 (patch-src_polkitagent_polkitagenthelper-pam.c) = 492baae7c3942765db2d7f89346386435671c280
SHA1 (patch-src_polkitbackend_polkitbackendduktapeauthority.c) = 5e48729c3414ccd41faa2e60bf3c915207e21cd1
SHA1 (patch-src_polkitbackend_polkitd.c) = e587e99017128477522050391c5410024a1e25c7
SHA1 (patch-src_programs_pkttyagent.c) = d9044bcc2ebd79a885c7bbc8327bdebab5680748
Index: security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c
--- security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c 2026-09-30 03:17:11
+++ security/polkit/patches/patch-src_polkitagent_polkitagenthelper-pam.c 2026-09-30 03:17:29
@@ -1,11 +1,38 @@
$NetBSD: patch-src_polkitagent_polkitagenthelper-pam.c,v 1.1 2025/12/21 15:44:05 wiz Exp $
-Fix build on NetBSD.
-https://github.com/polkit-org/polkit/pull/624
+Fix build where ENODATA is missing (FreeBSD, DragonFly, OpenBSD), and
+keep the NetBSD fix.
---- src/polkitagent/polkitagenthelper-pam.c.orig 2025-12-21 14:47:56.694667615 +0000
+polkit defines SO_PEERPIDFD itself when the system does not, with no
+platform test, so the socket-activation block is compiled everywhere,
+and inside it errno is compared against ENODATA. Two upstream commits,
+both after polkit 127, fix this:
+
+ 066b55bf2e2b polkitagenthelper-pam.c: ifdef out the socket activation
+ functionality
+ 72c28782b17e Fix build on systems without SO_PEERCRED.
+
+The first makes the fallback define Linux-only and wraps the block in
+#ifdef SO_PEERPIDFD; the second is the NetBSD fix this patch carried
+before. Remove when updating past 127.
+
+--- src/polkitagent/polkitagenthelper-pam.c.orig
+++ src/polkitagent/polkitagenthelper-pam.c
-@@ -141,7 +141,9 @@ main (int argc, char *argv[])
+@@ -38,7 +38,7 @@
+ # define SO_PEERPIDFD 0x404B
+ # elif defined(__sparc__)
+ # define SO_PEERPIDFD 0x0056
+-# else
++# elif defined(__linux__)
+ # define SO_PEERPIDFD 77
+ # endif
+ #endif
+@@ -137,11 +137,14 @@
+ goto error;
+ }
+
++#ifdef SO_PEERPIDFD
+ /* We are socket activated and the socket has been set up as stdio/stdout, read user from it */
if (argv[1] != NULL && strcmp (argv[1], "--socket-activated") == 0)
{
socklen_t socklen = sizeof(int);
@@ -15,7 +42,7 @@
user_to_auth_free = read_cookie (argc, argv);
if (!user_to_auth_free)
-@@ -165,8 +167,12 @@ main (int argc, char *argv[])
+@@ -165,8 +168,12 @@
goto error;
}
@@ -28,7 +55,7 @@
if (rc < 0)
{
syslog (LOG_ERR, "Unable to get credentials from socket");
-@@ -174,7 +180,9 @@ main (int argc, char *argv[])
+@@ -174,9 +181,12 @@
goto error;
}
@@ -37,4 +64,7 @@
+#endif
}
else
++#endif
user_to_auth = argv[1];
+
+ cookie = read_cookie (argc, argv);
Home |
Main Index |
Thread Index |
Old Index