handle_remove_local_ref validates the remote name but passes the ref
string directly to flatpak_dir_remove_ref without validation. Since the
polkit action for this method is modify-repo (allow_active=yes), any
active session user can delete arbitrary ostree refs in the system repo
without authentication.
All legitimate callers of RemoveLocalRef pass standard flatpak refs
(app/runtime). Non-standard refs like appstream/, appstream2/, and
ostree-metadata are managed through their own dedicated D-Bus methods
(DeployAppstream, UpdateRemote, ConfigureRemote) and never go through
RemoveLocalRef.
Validate the ref with flatpak_decomposed_new_from_ref() to restrict
removal to valid flatpak refs.
The Deploy authorization handler decides between app-install (requires
admin auth) and app-update (no auth needed) by checking whether the ref
is currently installed. The deploy handler then independently checks the
deployed state to decide whether to install or update.
Record the authorization decision on the invocation and verify in the
deploy handler that the operation matches what was authorized.
The --assumeyes (-y) option was setting both the CLI-level
disable_interaction flag and the library-level no_interaction flag to
TRUE. This caused -y to suppress not just confirmation prompts, but
also credential prompts (basic auth, webflow), polkit authorization
dialogs, and parental control consent -- even though -y is documented
as "automatically answer yes to all questions".
Rename disable_interaction to assume_yes to clarify its purpose: it
auto-answers yes/no confirmations and picks default choices. Stop
calling flatpak_transaction_set_no_interaction() from the CLI
transaction constructor, so the library-level no_interaction flag is
only set by --noninteractive (which uses FlatpakQuietTransaction).
Remove the assume_yes guard from basic_auth_start so credential
prompts are always shown when the CLI transaction is in use.
Assisted-by: Cursor
If flatpak is built with code coverage enabled, libgcov sometimes
helpfully emits messages in the output from programs under test.
If we’re strictly comparing the whole output of a program to an expected
string, as `test-history.sh` does in these two places, this can cause
spurious test failures.
Temporarily tell it to send its error messages to `/dev/null` as we
don’t care about them for those tests.
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.
Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
Instead of modifying the host-like run environment to clear the sandbox
environment, we'll use the new --clear-env flag which does the correct
thing.
Assisted-by: Claude:opus-4.6
Closes: #5271
This reverts commit a57f6bc372.
The run-environ from the calling instance is a host-like environment
(e.g. on NixOS it contains /nix/store paths). Passing it via --env
injects it into the sandbox payload environment where those paths don't
exist.
Revert the commit, so we pass run-environ as the envp for spawning
flatpak run again to let it make host-level decisions (DISPLAY,
FLATPAK_GL_DRIVERS, XDG_RUNTIME_DIR, etc.) without leaking into the
sandbox.
It also passes --clear-env unconditionally, because we'd build up the
environment, but the wrong one. We will implement --clear-env properly
again in the next few commits.
Closes: #6717
Fixes: a57f6bc3 ("portal: Clear the environment via flatpak arguments")
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
g_file_equal returns TRUE when paths are equal, so the != 0 check
was triggering a reload when the path was unchanged and keeping the
stale cache when the path changed to a different file.
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
The warning for a failed g_file_monitor_file call used error->message
but the error was stored in local_error. If polkit succeeded, error
is NULL, causing a NULL dereference.
Add the same early remote name validation (reject empty or containing
'/') that other D-Bus handlers already perform, for consistency. The
validation is not required for correctness or security but rejects
obviously invalid input at the entry point.
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
branch, commit, and app_path are read from the instance info key
file and could be NULL if the keys are missing. This would lead to
NULL dereferences in g_file_new_for_path, g_variant_new_string,
or printf %s. Fail early with an error instead.
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
The check tests sandbox_flags but the error message formatted
arg_flags, showing unrelated spawn flags instead of the actual
unsupported sandbox flags.
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because
evaluator (condition) == !negated
... and the evaluator evaluates unknown conditions as false.
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).
Let's just error out as early as possible to avoid those weird
half-initialized cases.
That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.
Also fix the header guard while at it.
Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.
This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.
The code checked the wrong flags. struct_props is the array of child
properties, so struct_props->flags is the flags of the first child
property. What we need to chech is the flags of the current property,
and if it contains FLATPAK_JSON_PROP_FLAGS_STRICT.