system-helper: Validate ref in RemoveLocalRef

handle_remove_local_ref validates the remote name but passes the ref
string directly to flatpak_dir_remove_ref without validation. Since the
polkit action for this method is modify-repo (allow_active=yes), any
active session user can delete arbitrary ostree refs in the system repo
without authentication.

All legitimate callers of RemoveLocalRef pass standard flatpak refs
(app/runtime). Non-standard refs like appstream/, appstream2/, and
ostree-metadata are managed through their own dedicated D-Bus methods
(DeployAppstream, UpdateRemote, ConfigureRemote) and never go through
RemoveLocalRef.

Validate the ref with flatpak_decomposed_new_from_ref() to restrict
removal to valid flatpak refs.
This commit is contained in:
Sebastian Wick committed 2026-08-04 11:38:22 +00:00
1 parent 52be0a8a9a
commit 660d3dfcfd
1 file changed
+8
+8
View File
@@ -1255,6 +1255,7 @@ handle_remove_local_ref (FlatpakSystemHelper *object,
const gchar *arg_installation)
{
g_autoptr(FlatpakDir) system = NULL;
g_autoptr(FlatpakDecomposed) ref = NULL;
g_autoptr(GError) error = NULL;
g_info ("RemoveLocalRef %u %s %s %s", arg_flags, arg_remote, arg_ref, arg_installation);
@@ -1280,6 +1281,13 @@ handle_remove_local_ref (FlatpakSystemHelper *object,
return G_DBUS_METHOD_INVOCATION_HANDLED;
}
ref = flatpak_decomposed_new_from_ref (arg_ref, &error);
if (ref == NULL)
{
g_dbus_method_invocation_return_gerror (invocation, error);
return G_DBUS_METHOD_INVOCATION_HANDLED;
}
if (!flatpak_dir_ensure_repo (system, NULL, &error))
{
g_dbus_method_invocation_return_gerror (invocation, error);