From 52be0a8a9a5f1e74951aa12ef9c4e957656c2f2d Mon Sep 17 00:00:00 2001 From: Sebastian Wick Date: Thu, 2 Jul 2026 19:18:10 +0200 Subject: [PATCH] system-helper: Ensure deploy authorization matches operation The Deploy authorization handler decides between app-install (requires admin auth) and app-update (no auth needed) by checking whether the ref is currently installed. The deploy handler then independently checks the deployed state to decide whether to install or update. Record the authorization decision on the invocation and verify in the deploy handler that the operation matches what was authorized. --- system-helper/flatpak-system-helper.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/system-helper/flatpak-system-helper.c b/system-helper/flatpak-system-helper.c index 89626d3cc..eecd3405d 100644 --- a/system-helper/flatpak-system-helper.c +++ b/system-helper/flatpak-system-helper.c @@ -458,6 +458,17 @@ handle_deploy (FlatpakSystemHelper *object, deploy_dir = flatpak_dir_get_if_deployed (system, ref, NULL, NULL); is_update = (deploy_dir && !reinstall); + + if (!is_update && + GPOINTER_TO_INT (g_object_get_data (G_OBJECT (invocation), + "authorized-as-update"))) + { + g_dbus_method_invocation_return_error (invocation, G_DBUS_ERROR, G_DBUS_ERROR_FAILED, + "Ref %s is not installed, but install was not authorized", + flatpak_decomposed_get_ref (ref)); + return G_DBUS_METHOD_INVOCATION_HANDLED; + } + if (is_update) { g_autofree char *real_origin = NULL; @@ -1970,6 +1981,11 @@ flatpak_authorize_method_handler (GDBusInterfaceSkeleton *interface, is_install = !dir_ref_is_installed (system, ref); } + if (!is_install) + g_object_set_data (G_OBJECT (invocation), + "authorized-as-update", + GINT_TO_POINTER (TRUE)); + if (is_install) { if (is_app)