[Pkg-utopia-maintainers] Bug#1136196: pkexec: allow_gui annotation no longer preserves DISPLAY/XAUTHORITY

Fabio Fantoni fantonifabio at tiscali.it
Sun Jul 12 19:19:49 BST 2026


Control: retitle -1 pkexec: exec.path annotation no longer matches when 
the program path is a symlink (realpath change in 127)


I found the root cause of this issue.

Since polkit 127, pkexec resolves the program path with realpath(3) 
*before* matching it against the org.freedesktop.policykit.exec.path 
annotations. This comes from upstream commit 
9aa43e089d870a8ee695e625237c5b731b250678 ("pkexec: Use realpath when 
comparing org.freedesktop.policykit.exec.path"), which was meant to 
handle usrmerge aliasing (/bin/foo vs /usr/bin/foo, upstream issue 
polkit-org/polkit#194).

The annotation match in find_action_for_path() is an exact string 
comparison, so if the annotated path is a symlink the resolved path no 
longer matches, the action is silently not found, and pkexec falls back 
to the implicit action. As a consequence allow_gui is not applied 
(DISPLAY and XAUTHORITY get stripped), and any custom defaults/message 
of the action are ignored as well.

In my case: /usr/bin/bleachbit is a symlink to 
/usr/share/bleachbit/bleachbit.py, so the org.bleachbit action (which 
has allow_gui=true, as shown by pkaction) is no longer matched. 
allow_gui itself is not broken: the same annotation works if the 
annotated path is not a symlink. This also explains why manually passing 
the variables with "pkexec env DISPLAY=... XAUTHORITY=..." works.

So the behavior contradicts both the pkexec(1) manpage (which still says 
DISPLAY/XAUTHORITY are retained when allow_gui is set) and the 
least-surprise expectation for packages whose entry point in /usr/bin is 
a symlink (fairly common for interpreted programs). The upstream commit 
message itself warned "a review of your <annotate 
key=\"org.freedesktop.policykit.exec.path\"> actions might be in order", 
but nothing was documented in NEWS or the manpage, and affected actions 
fail silently.

Possible fixes on the polkit side:
- match the annotation against both the pre-realpath absolute path and 
the resolved one (or also canonicalize the annotation value before 
comparing), or
- at minimum document the behavior change in pkexec(1)/NEWS so packages 
know they must annotate the canonical path.

I have worked around it in bleachbit by shipping a second action with 
the resolved path (keeping the old one for pkexec < 127), which will be 
in bleachbit 6.0.2-1. Other packages with symlinked exec.path 
annotations are likely affected in the same way.

Please consider forwarding this upstream 
(https://github.com/polkit-org/polkit/issues).

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260712/066ec2f7/attachment.sig>


More information about the Pkg-utopia-maintainers mailing list