Commit Graph
8541 Commits
Author SHA1 Message Date
Sebastian Wick 37fe50fc9c installation: Avoid races when caching the display name
We specifically have to avoid holding the lock while calling
flatpak_installation_get_dir_maybe_no_repo, so we just double check if
it is unset.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2a0c49ef89 flatpak-json: Fix strict struct JSON parsing
The code checked the wrong flags. struct_props is the array of child
properties, so struct_props->flags is the flags of the first child
property. What we need to chech is the flags of the current property,
and if it contains FLATPAK_JSON_PROP_FLAGS_STRICT.
2026-07-27 13:41:00 +00:00
Sebastian Wick c4d12fa6ad zstd-compressor: Abort on ZSTD_initCStream error
This doesn't seem to happen in practice, but the API says it's possible,
so we better abort than run into weird states.
2026-07-27 13:41:00 +00:00
Sebastian Wick a68d120bc1 image-source: Handle NULL commit subjects and bodies 2026-07-27 13:41:00 +00:00
Sebastian Wick 1825293e27 run: Add error handling for g_unix_fd_list_append
It also adds autofd cleanup and simplifies the control flow a bit.
2026-07-27 13:41:00 +00:00
Sebastian Wick 6dd9768d73 run: Fix the inverted behavior of --clear-env
Copy and paste error which results in the default and explicit usage of
--clear-env to be inverted.

Fixes: f760f1b5 ("run: Add --clear-env option for clearing the outside environment")
2026-07-27 13:41:00 +00:00
Sebastian Wick 59ef3bc49a usb: Parse the vnd rule into the vendor union member
It was accidentally parsed into the product union member but because it
has the same layout as the vendor one, this didn't turn into a bug in
practice, but it probably is UB.
2026-07-27 13:41:00 +00:00
Sebastian Wick e881563fd4 remote-ref: Fix the get_property of the download-size property 2026-07-27 13:41:00 +00:00
Sebastian Wick 027cd64af0 xml-utils: Escape XML attribute values when serializing 2026-07-27 13:41:00 +00:00
Sebastian Wick 7ecf90f1dd json-oci: Clean up dead code in flatpak_oci_index_get_manifest_for_arch 2026-07-27 13:41:00 +00:00
Sebastian Wick d2f364bbd7 locale-utils: Ensure the flatpak lang only contains a-zA-Z
This should be the case anyway right now and makes it easier to ensure
the code using it is correct.
2026-07-27 13:41:00 +00:00
Sebastian Wick c771d52887 dir-utils: Fix return type in flatpak_find_current_ref 2026-07-27 13:41:00 +00:00
filmsi 478d355cd2 Update sl.po
Updated Slovenian translation.
2026-07-06 10:24:43 +00:00
Maximiliano Sandoval 59f9a7729f common: Stop using G_GNUC_CONST in _get_type funcs
As per g_type_ensure's documentation it is technically incorrect to mark
_get_type fns with G_GNUC_CONST since they have side-effects on their
first run.

See https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5223 for more
details.
2026-07-06 08:23:01 +00:00
Mia McMahill aeb3783117 flatpak-coredumpctl: Explicitly indicate type for DebugDumpArgs.target
Fixes a type check error with mypy
Other members had their type hints moved to the
class body as well for consistency
2026-07-05 01:12:35 +00:00
Mia McMahill cc5080bbcd flatpak-coredumpctl: Create main function called from __main__
This constraints the scope of the variables within instead of
unnecessarily creating global variables, and it makes it easier to keep
only a single sys.exit
2026-07-05 01:12:35 +00:00
Mia McMahill e52dd01251 flatpak-coredumpctl: Check for coredumpctl installation in main
coredumpctl is required for both subcommands, and likely will be for any
others added in the future, so we should just check for it in one place
at the start.
2026-07-05 01:12:35 +00:00
Mia McMahill 39c7f52e40 flatpak-coredumpctl: Add 'flatpak-coredumpctl list' command
Reworks the interface of flatpak-coredumpctl to use subcommands
similar to those of coredumpctl. The new list subcommand is currently
non-functional, but will list all store coredumps from flatpak
applications, and the previous debugger functionality has been moved to
the debug subcommand.

flatpak-coredumpctl: Implement basic functionality for 'list' subcommand

Resolves #2002: 'flatpak-coredumpctl list' now lists coredumps
in a format similar to coredumpctl, except that it skips inaccessible
coredumps by default

flatpak-coredumpctl: Use a pager for list output

These less flags don't perfectly match coredumpctl because it uses
systemd's pager instead of less, but it's close enough

flatpak-coredumpctl: Match coredumpctl's text styling

The column titles are now underlined and missing/inaccessible coredumps
are grayed out.
This is probably just a little overengineered for what is needed, but I
wanted to make it easy to expand in the future if needed, and it is
still fairly minimal.

flatpak-coredumpctl: Add matches argument to list subcommand
2026-07-05 01:12:35 +00:00
John Cardullo f653896b18 tests: Add test cases for file-forwarding in test-run.sh
Add regression tests to verify that remote URIs and local files can
be forwarded correctly, and that empty paths result in an error.
2026-07-03 17:16:06 +00:00
John Cardullo f266346d6d run: Validate file object before checking cached path
Verify that the file object is valid before checking its cached path
to avoid a potential NULL pointer dereference.

Fixes: c4fce9e4 ("run: Error out if file forwarding of empty paths is attempted")
2026-07-03 17:16:06 +00:00
Yuri Chornoivan d34956a0d8 Update Ukrainian translation 2026-06-23 10:35:44 +00:00
razzeee 4006907ba3 transaction: Add flatpak_transaction_progress_get_bytes_per_second() 2026-06-23 09:50:04 +00:00
bbhtt 5fcf748ac9 dir: Don't pass temp repo path to flatpak_dir_log during initial pull
During a system install with the system helper enabled, the initial
network pull goes to a temporary repo and then via pull local from that
repo to the final system repo while during user install there is only
one pull from network to the final repo.

c672c55 set the logger to use the temporary repo path as installation
but the history command afc87ad since the same day filters the initial
pull out as the installation name will never match the temporary path.

This causes the initial pull operation to be never show up in flatpak
history when using system installs while they work for user installs as
`INSTALLATION=user`.

This is presumably also broken for custom installations as they
will similarly not match the temp repo path.

So don't pass the path at all to flatpak_dir_log and we can later
fall back via flatpak_dir_get_name_cached() which sets the correct
`INSTALLATION` for system installs ie. `INSTALLATION=system`.

This also allows us to remove the workaround of adding two different
expected history outputs from ad1ff6d as both branches log the pull.

Without system helper `flatpak install` needs to be executed as
priviledged to operate on system install so the initial pull was
always logged correctly for that branch.
2026-06-23 09:11:59 +00:00
Mia McMahill a9215f4153 flatpak-coredumpctl: Clean up usage messages slightly with metavar
This just makes the generated messages slightly less redundant and a
little closer to coredumpctl's.
2026-06-23 09:05:14 +00:00
Mia McMahill aef5cf91a3 flatpak-coredumpctl: Make use of periods consistent in help messages
Help messages were inconsistent about whether they ended with periods or
not. I chose to remove the periods from those that had them rather than
the other way around because the help messages automatically generated
by argparse do not have periods.
2026-06-23 09:05:14 +00:00
Mia McMahill 32698f1e60 flatpak-coredumpctl: Refactor arg validation to have no typecheck errors
There are a couple related changes made here, with the intention of
making it easier to implement additional features in the future:
- Mutual exclusivity of --build-directory and app is better enforced
  both through types and at runtime. The types will let type checkers
  ensure that we cannot reach the run function without at least one of
  them being valid. At runtime, it no longer allows both to be
  specified, which could result in confusion over which takes
  precedence.
- Instead of wrapping the entire program in a class, there is now only a
  small class that handles validation of the arguments and holding the
  data to be passed to run. This provides a better separation of
  concerns, with the argument parsing now being a little less tied to
  running the debugger.
2026-06-23 09:05:14 +00:00
Mia McMahill dbdddd4bd5 flatpak-coredumpctl: Only call sys.exit from main 2026-06-23 09:05:14 +00:00
Mia McMahill e77bb49d88 flatpak-coredumpctl: Remove nargs="?" from -m option
-m with no argument currently results in coredumpctl_matches having a
value of "", which is exactly the same as if it weren't used at all. As
far as I can tell, allowing this does nothing useful, only making the
usage slightly less clear.
2026-06-23 09:05:14 +00:00
bbhtt f4946b206b flatpak-context: Add test for flatpak_permission_to_args negated output
Test for the bug fixed in db70882d. We test no(socket | device) anyway
to stop future regressions.
2026-06-23 08:46:20 +00:00
Sebastian Wick ce4a27e1fe portal: Check if the monitor is closed before emitting progress
`emit_progress` is called from a thread while another thread could
unexport/close the GDbusInterfaceSkeleton. If that happens, the
connection becomes NULL which is illegal for
`g_dbus_connection_emit_signal` which results in dereferencing an unset
error.

The fix is to lock the UpdateMonitorData, and then only emit the signal
if it is not closed.
2026-06-23 08:45:08 +00:00
Sebastian Wick c4fce9e42a run: Error out if file forwarding of empty paths is attempted
The file forwarding feature errors out when the path or URI does not
lead to an actual file that can be forwarded. The empty path never
describes an actual file, so we always have to error out.

Without the check, we would get a NULL path from
`flatpak_file_get_path_cached` and crash later.

Closes: #6689
2026-06-23 08:44:34 +00:00
꧁★☆ 𝚖𝚒𝚐𝚞𝚎𝚕𝟶𝟺𝟼𝟾𝟻 ☆★꧂ fdb1741789 Update Brazilian Portuguese translation 2026-06-19 08:13:21 +05:30
bbhtt ad1ff6da68 tests: Fix expected history output when system helper is compiled out
Pulls do not go to the temp repo so they are logged when system
helper is compiled out
2026-06-18 21:15:41 +00:00
bbhtt d820c4bc5e tests: Fix FL_CACHE_DIR when system helper is compiled out
The tests assumed that a system installation always uses the XDG cache
location unless running as root. However, Flatpak only uses that cache
location when the system helper is available at both compile and run
time. [1]

Builds configured with -Dsystem_helper=disabled instead use the
repo-local cache directory [2], causing the tests to look for cached
summaries in the wrong location and fail.

[1]: https://github.com/flatpak/flatpak/blob/96ad6825f3e7115eb95abeba55600b2a39b71178/common/flatpak-dir.c#L4853-L4862
[2]: https://github.com/flatpak/flatpak/blob/96ad6825f3e7115eb95abeba55600b2a39b71178/common/flatpak-dir.c#L4942-L4943
2026-06-18 21:15:41 +00:00
bbhtt 489b3972cb tests: Skip seccomp tests when seccomp is unavailable
Fixes the testsuite with `-Dseccomp=disabled`.
2026-06-18 21:15:41 +00:00
Sebastian Wick f7138cbbc3 Update subtree: libglnx 2026-06-18
* backports, local-alloc: Provide a backport of g_autofd
* build: Add meson.override_dependency('libglnx', libglnx_dep)
* fdio: Add support for name_to_handle_at
* chase: Add glnx_chase_and_mkdirat

Signed-off-by: Sebastian Wick <sebastian.wick@redhat.com>
2026-06-18 14:09:38 +02:00
Mia McMahill a9766fbcbd ci: Bump differential shellcheck to v5 2026-06-18 11:18:12 +00:00
Mia McMahill f4512ef55e ci: Bump CodeQL actions to v4
This addresses CodeQL v3 and Node 20 deprecation warnings
2026-06-18 11:18:12 +00:00
Mia McMahill 84271a64c4 ci: Bump actions/checkout to v6 and actions/upload-artifact to v7
This addresses the Node 20 deprecation warnings
2026-06-18 11:18:12 +00:00
Mia McMahill 02fc85a3c2 completion: Minor cleanup of variable usage in bash completion
1. Removed unnecessary punctuation to help with readability
2. Loop over RES elements directly instead of indexing
3. Declare COMPGEN_OPTS only once vs redeclaring on each iteration
2026-06-18 11:15:54 +00:00
Mia McMahill 21ae7723c0 completion: Address a couple shellcheck warnings
1. Use $() command substitution instead of legacy `` style
2. Properly quote COMPGEN_OPTS
3. Use readarray instead of relying on word splitting
2026-06-18 11:15:54 +00:00
Mia McMahill 9047dabfaf completion: Make all variables local where possible in bash completion
A few global variables were being created unecessarily still. This makes
sure that users shell environments are not polluted by extra variables
and that the completion doesn't modify unrelated variables
2026-06-18 11:15:54 +00:00
Sebastian Wick 8ef5ee9455 Merge branch 'wip/chase-callback' into 'master'
chase: Add glnx_chase_and_mkdirat

See merge request GNOME/libglnx!76
2026-06-17 12:30:57 +00:00
Sebastian Wick ae7355612a chase: Add glnx_chase_and_mkdirat
We found that there is a common use case where we need to get a
subdirectory (potentially multiple levels) which might not exist yet.
Adding another flag for this to GlnxChaseFlags is what systemd has done,
but creating a directory takes a mode, so the flag creates directories
with a fixed mode. This approach instead takes the mode as argument.
2026-06-17 14:27:41 +02:00
Sebastian Wick 4f8674709d chase: Add internal glnx_chaseat_full for a strategic callback
It takes a callback which gets called every time we try to open the next
segment of the path. This allows implementing more specific and advanced
use cases to be implemented without adding more complexity to the chase
algorithm itself.
2026-06-17 14:27:16 +02:00
Owen W. Taylor 906affa13b Handle null properties as missing properties
We were handling null properties the same as missing properties
*except* that the MANDATORY flag allowed null properties but
not missing properties. Fix this, so null is disallowed by
MANDATORY.

When checking signatures, the image identity could only have
been NULL if it was null in the input file - so replace a
conditional check on it being non-null with an assertion.
2026-06-16 20:13:10 +00:00
Owen W. Taylor b15828e119 Fix crash on image indexes with missing architecture
It's legitimate to have manifests listed in an image index that
have no platform object, and hence no architecture - avoid crashing
if we encounter such a manifest.
2026-06-16 20:13:10 +00:00
Owen W. Taylor fa4b413c02 Make mandatory properties from OCI specifications mandatory
Mark all properties required by the OCI specification as required;
this eliminates a bunch of cases where we were assuming that
descriptor->digest was non-NULL, and potentially generating
critical errors from g_return_if_fail().
2026-06-16 20:13:10 +00:00
Mia McMahill 4d3f0bbb79 app, common: Remove duplicate directories from export functions
Both collect exports and flatpak_export_dir recursively export the
directories in their respective directory lists. Because of this,
including share/metainfo/releases when share/metainfo is already in the
lists is unnecessary and can cause exporting to fail because of
duplicate files.
2026-06-16 11:20:58 +00:00
Mia McMahill cebc323966 tests: Add test for building and installing with exported releases.xml
Adds a test that verifies releases.xml metainfo files are not duplicated
at any export stage, and that they are not left unexported either.
2026-06-16 11:20:58 +00:00