Package: linux-entra-sso
Version: 1.8.1-1
Severity: important
Tags: patch upstream
Hi !
I've been getting error
Failed to load data from broker: {"context":"msalCppVersion is NULL
orEMPTY","diagnostics":{"raw_error_code":"illegal_argument_exception","exception_type":"com.microsoft.identity.common.exception.ArgumentException","illegal_argument_name":"msalCppVersion"},"errorCode":0,"status":6,"subStatus":0,"tag":0}".
when trying to use the extension. It looks like the cause is that
/usr/libexec/linux-entra-sso/linux-entra-sso.py contains:
LINUX_ENTRA_SSO_VERSION = ""
Which makes the M$ broker rather unhappy.
I confirmed this happens with the current sid package
(linux-entra-sso_1.8.1-1_all.deb).
The reason is that the version is "patched" into the script by the
Makefile, and it derives the version solely from git describe:
RELEASE_TAG ?= $(shell git describe --match "v[0-9].[0-9]*" --dirty)
WEBEXT_VERSION=$(RELEASE_TAG:v%=%)
UPDATE_VERSION_PY='s|0.0.0-dev|$(WEBEXT_VERSION)|g' # used in install:
When building from the release tarball there is no git repository, so
git describe outputs nothing, WEBEXT_VERSION is empty, and the install
target's sed rewrites the "0.0.0-dev" placeholder in linux-entra-sso.py
to an empty string. debian/rules calls "dh_auto_install -- prefix=/usr"
with no version override, so nothing repairs it.
A fix is to pass the upstream version from the changelog to the Makefile
so it is never empty:
DEB_VERSION_UPSTREAM := $(shell dpkg-parsechangelog -SVersion | sed
's/-[^-]*$$//')
override_dh_auto_install:
dh_auto_install -- prefix=/usr RELEASE_TAG=v$(DEB_VERSION_UPSTREAM)
Attached is an AI generated patch (thanks Claude) as I am not familiar
with Debian build system.
-- System Information:
Debian Release: (Ubuntu 26.04.1 LTS derivative)
Architecture: amd64
Kernel: Linux 7.0.0-31-generic
Locale: LANG=en_US.UTF-8
Versions of packages linux-entra-sso is related to:
ii microsoft-identity-broker 2.0.1
ii python3-gi 3.56.2-1
ii python3-pydbus 0.6.0-6
--- a/debian/rules
+++ b/debian/rules
@@ -1,12 +1,20 @@
#!/usr/bin/make -f
+# The upstream Makefile derives the version solely from 'git describe',
+# which yields nothing when building from the release tarball. That empty
+# version is baked into linux-entra-sso.py as LINUX_ENTRA_SSO_VERSION and
+# later sent to the Microsoft Identity Broker as msalCppVersion, which the
+# broker rejects ("msalCppVersion is NULL or EMPTY"), breaking SSO.
+# Pass the upstream version from the changelog so it is never empty.
+DEB_VERSION_UPSTREAM := $(shell dpkg-parsechangelog -SVersion | sed 's/-[^-]*$$//')
+
%:
dh $@
override_dh_auto_build:
override_dh_auto_install:
- dh_auto_install -- prefix=/usr
+ dh_auto_install -- prefix=/usr RELEASE_TAG=v$(DEB_VERSION_UPSTREAM)
# Use debian/postinst to install the Chrome conffile
# and debian/postrm to remove it since dpkg's automatic