From b8ccd50e0eae58e11d0d121f3fa05746e0d24ee2 Mon Sep 17 00:00:00 2001 From: Markus Volk Date: Mon, 11 Mar 2024 08:56:31 +0100 Subject: [PATCH] polkit: remove unneeded workaround polkitd doesn't segfault with MemoryDenyWriteExecute=yes anymore Signed-off-by: Markus Volk Signed-off-by: Khem Raj --- ...ce.in-disable-MemoryDenyWriteExecute.patch | 30 ------------------- meta-oe/recipes-extended/polkit/polkit_124.bb | 4 +-- 2 files changed, 1 insertion(+), 33 deletions(-) delete mode 100644 meta-oe/recipes-extended/polkit/polkit/0001-polkit.service.in-disable-MemoryDenyWriteExecute.patch diff --git a/meta-oe/recipes-extended/polkit/polkit/0001-polkit.service.in-disable-MemoryDenyWriteExecute.patch b/meta-oe/recipes-extended/polkit/polkit/0001-polkit.service.in-disable-MemoryDenyWriteExecute.patch deleted file mode 100644 index 4f008f7a97..0000000000 --- a/meta-oe/recipes-extended/polkit/polkit/0001-polkit.service.in-disable-MemoryDenyWriteExecute.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 95148a804be66092564f81306a02f625d5b8a5d0 Mon Sep 17 00:00:00 2001 -From: Markus Volk -Date: Sun, 17 Sep 2023 23:26:59 +0200 -Subject: [PATCH] polkit.service.in: disable MemoryDenyWriteExecute - -A few momths ago some hardening options have been added to polkit.service.in -https://gitlab.freedesktop.org/polkit/polkit/-/merge_requests/177/diffs?commit_id=afecbd53696e32bbadd60f431fc7d285f3edd265 - -and polkitd segfaults with MemoryDenyWriteExecute=yes, at least in my environment - -Upstream-Status: Inappropriate [needs further investigation] - -Signed-off-by: Markus Volk ---- - data/polkit.service.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/data/polkit.service.in b/data/polkit.service.in -index e6db351..4390cce 100644 ---- a/data/polkit.service.in -+++ b/data/polkit.service.in -@@ -12,7 +12,7 @@ ExecStart=@libprivdir@/polkitd --no-debug - User=@polkitd_user@ - LimitMEMLOCK=0 - LockPersonality=yes --MemoryDenyWriteExecute=yes -+#MemoryDenyWriteExecute=yes - NoNewPrivileges=yes - PrivateDevices=yes - PrivateNetwork=yes diff --git a/meta-oe/recipes-extended/polkit/polkit_124.bb b/meta-oe/recipes-extended/polkit/polkit_124.bb index 3eb0d52806..9e2eb05c62 100644 --- a/meta-oe/recipes-extended/polkit/polkit_124.bb +++ b/meta-oe/recipes-extended/polkit/polkit_124.bb @@ -4,9 +4,7 @@ HOMEPAGE = "http://www.freedesktop.org/wiki/Software/polkit" LICENSE = "LGPL-2.0-or-later" LIC_FILES_CHKSUM = "file://COPYING;md5=155db86cdbafa7532b41f390409283eb" -SRC_URI = "git://gitlab.freedesktop.org/polkit/polkit.git;protocol=https;branch=master \ - file://0001-polkit.service.in-disable-MemoryDenyWriteExecute.patch \ - " +SRC_URI = "git://gitlab.freedesktop.org/polkit/polkit.git;protocol=https;branch=master" S = "${WORKDIR}/git" SRCREV = "82f0924dc0eb23b9df68e88dbaf9e07c81940a5a"