mirror of
https://github.com/flatpak/flatpak.git
synced 2026-10-06 12:59:38 -04:00
system-helper: Validate ref in RemoveLocalRef
handle_remove_local_ref validates the remote name but passes the ref string directly to flatpak_dir_remove_ref without validation. Since the polkit action for this method is modify-repo (allow_active=yes), any active session user can delete arbitrary ostree refs in the system repo without authentication. All legitimate callers of RemoveLocalRef pass standard flatpak refs (app/runtime). Non-standard refs like appstream/, appstream2/, and ostree-metadata are managed through their own dedicated D-Bus methods (DeployAppstream, UpdateRemote, ConfigureRemote) and never go through RemoveLocalRef. Validate the ref with flatpak_decomposed_new_from_ref() to restrict removal to valid flatpak refs.
This commit is contained in:
1 parent
52be0a8a9a
commit
660d3dfcfd
1 file changed
+8
@@ -1255,6 +1255,7 @@ handle_remove_local_ref (FlatpakSystemHelper *object,
|
||||
const gchar *arg_installation)
|
||||
{
|
||||
g_autoptr(FlatpakDir) system = NULL;
|
||||
g_autoptr(FlatpakDecomposed) ref = NULL;
|
||||
g_autoptr(GError) error = NULL;
|
||||
|
||||
g_info ("RemoveLocalRef %u %s %s %s", arg_flags, arg_remote, arg_ref, arg_installation);
|
||||
@@ -1280,6 +1281,13 @@ handle_remove_local_ref (FlatpakSystemHelper *object,
|
||||
return G_DBUS_METHOD_INVOCATION_HANDLED;
|
||||
}
|
||||
|
||||
ref = flatpak_decomposed_new_from_ref (arg_ref, &error);
|
||||
if (ref == NULL)
|
||||
{
|
||||
g_dbus_method_invocation_return_gerror (invocation, error);
|
||||
return G_DBUS_METHOD_INVOCATION_HANDLED;
|
||||
}
|
||||
|
||||
if (!flatpak_dir_ensure_repo (system, NULL, &error))
|
||||
{
|
||||
g_dbus_method_invocation_return_gerror (invocation, error);
|
||||
|
||||
Reference in new issue
Block a user