[Pkg-utopia-maintainers] Bug#1144434: polkitd: please enable polkit-agent-helper.socket statically in /usr

Martin Pitt mpitt at debian.org
Sat Aug 15 06:50:58 BST 2026


Package: polkitd
Version: 127-3
Severity: normal

Dear Maintainer,

polkit authentication is broken on systems whose /etc does not come from this
package's postinst, i.e. on image based systems where only /usr is shipped and
updated:

  polkit-agent-helper-1: needs to be setuid root
  Error: Incorrect permissions on /usr/lib/polkit-1/polkit-agent-helper-1
  (needs to be setuid root)

I hit this on ParticleOS (https://github.com/systemd/particleos).

Analysis
--------

Since 127, polkit-agent-helper-1 is no longer setuid root; privilege
escalation goes through the socket activated polkit-agent-helper.socket
instead. libpolkit-agent-1 falls back to spawning the setuid helper when
it cannot reach the socket.

  Cannot connect to helper via /run/polkit/agent-helper.socket, falling
  back to spawn suid helper instead: %s

The postinst deliberately (and correctly) does not set the setuid bit there.

The socket is enabled by dh_installsystemd, i.e. through a symlink that
the postinst creates in /etc/systemd/system/sockets.target.wants/. On an
image based system /etc is created once, at first boot, and then persists
across image updates. Packages added to the image later - or a system
switched to a different image - therefore never get that symlink, and
polkit stays broken with no indication of why.

Proposed fix
------------

Please ship the enablement symlink in /usr instead:

  usr/lib/systemd/system/sockets.target.wants/polkit-agent-helper.socket
      -> ../polkit-agent-helper.socket

i.e. add it to debian/polkitd.links and pass --no-enable to
dh_installsystemd for this unit.

Ideally also drop the [Install] section from polkit-agent-helper.socket, so
that "systemctl is-enabled" reports "static" rather than "disabled" for a unit
that is in fact active (but that is an upstream change).

dbus-system-bus-common already ships exactly this symlink for dbus.socket, and
plymouth, systemd-container and systemd-cryptsetup do the same for their units.
It is the right mechanism whenever a unit is not optional for the package to
function, which is the case here: without the socket, polkit cannot
authenticate at all.

It also makes the enablement independent of /etc state on ordinary
installations, e.g. when /etc/systemd/system was restored from a backup or
carried over from another installation.

Thanks,

Pitti



More information about the Pkg-utopia-maintainers mailing list