Commit Graph
8589 Commits
Author SHA1 Message Date
Sebastian Wick 660d3dfcfd system-helper: Validate ref in RemoveLocalRef
handle_remove_local_ref validates the remote name but passes the ref
string directly to flatpak_dir_remove_ref without validation. Since the
polkit action for this method is modify-repo (allow_active=yes), any
active session user can delete arbitrary ostree refs in the system repo
without authentication.

All legitimate callers of RemoveLocalRef pass standard flatpak refs
(app/runtime). Non-standard refs like appstream/, appstream2/, and
ostree-metadata are managed through their own dedicated D-Bus methods
(DeployAppstream, UpdateRemote, ConfigureRemote) and never go through
RemoveLocalRef.

Validate the ref with flatpak_decomposed_new_from_ref() to restrict
removal to valid flatpak refs.
2026-08-04 11:38:22 +00:00
Sebastian Wick 52be0a8a9a system-helper: Ensure deploy authorization matches operation
The Deploy authorization handler decides between app-install (requires
admin auth) and app-update (no auth needed) by checking whether the ref
is currently installed. The deploy handler then independently checks the
deployed state to decide whether to install or update.

Record the authorization decision on the invocation and verify in the
deploy handler that the operation matches what was authorized.
2026-08-04 11:38:22 +00:00
Sebastian Wick 6b7872d7ed system-helper: Drop supplementary groups
In case something takes over the process, not having any supplementary
groups limits the damage that can be done.
2026-08-04 11:38:22 +00:00
Sebastian Wick 41cb4118d1 bwrap: Warn when we failed to add a bind mount 2026-08-04 11:38:22 +00:00
Sebastian Wick f6102c528e context: Add comment to adds_permissions explaining what we do not check 2026-08-04 11:38:22 +00:00
Anders Jonsson cea48f27d2 Update Swedish translation 2026-08-03 11:15:19 +00:00
Luigi Pavan 0717cd1685 cli: Don't set no_interaction for --assumeyes
The --assumeyes (-y) option was setting both the CLI-level
disable_interaction flag and the library-level no_interaction flag to
TRUE. This caused -y to suppress not just confirmation prompts, but
also credential prompts (basic auth, webflow), polkit authorization
dialogs, and parental control consent -- even though -y is documented
as "automatically answer yes to all questions".

Rename disable_interaction to assume_yes to clarify its purpose: it
auto-answers yes/no confirmations and picks default choices. Stop
calling flatpak_transaction_set_no_interaction() from the CLI
transaction constructor, so the library-level no_interaction flag is
only set by --noninteractive (which uses FlatpakQuietTransaction).
Remove the assume_yes guard from basic_auth_start so credential
prompts are always shown when the CLI transaction is in use.

Assisted-by: Cursor
2026-07-29 09:42:26 +00:00
Philip Withnall da47d3b236 tests: Prevent gcov warnings spuriously failing test-history.sh
If flatpak is built with code coverage enabled, libgcov sometimes
helpfully emits messages in the output from programs under test.

If we’re strictly comparing the whole output of a program to an expected
string, as `test-history.sh` does in these two places, this can cause
spurious test failures.

Temporarily tell it to send its error messages to `/dev/null` as we
don’t care about them for those tests.

Signed-off-by: Philip Withnall <pwithnall@gnome.org>
2026-07-27 18:55:32 +00:00
Alexander Vanhee 7777fea6c1 system-helper: Authenticate via polkit for system wide downgrades
Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.

Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
2026-07-27 14:17:06 +00:00
Sebastian Wick d82c247cde portal: Test that the different envs get created as expected
Assisted-by: Claude:opus-4.6
2026-07-27 13:51:16 +00:00
Sebastian Wick 21a9692718 portal: Cleanup getting the host-like environment for flatpak-run 2026-07-27 13:51:16 +00:00
Sebastian Wick afbabdc32c portal: Pass run-environ to the spawned flatpak process, not the sandbox
Instead of modifying the host-like run environment to clear the sandbox
environment, we'll use the new --clear-env flag which does the correct
thing.

Assisted-by: Claude:opus-4.6
Closes: #5271
2026-07-27 13:51:16 +00:00
Sebastian Wick 7322a05c7f portal: Clear error after warning to avoid issues on the next error 2026-07-27 13:51:16 +00:00
Sebastian Wick b9fb6d4e25 Revert "portal: Clear the environment via flatpak arguments"
This reverts commit a57f6bc372.

The run-environ from the calling instance is a host-like environment
(e.g. on NixOS it contains /nix/store paths). Passing it via --env
injects it into the sandbox payload environment where those paths don't
exist.

Revert the commit, so we pass run-environ as the envp for spawning
flatpak run again to let it make host-level decisions (DISPLAY,
FLATPAK_GL_DRIVERS, XDG_RUNTIME_DIR, etc.) without leaking into the
sandbox.

It also passes --clear-env unconditionally, because we'd build up the
environment, but the wrong one. We will implement --clear-env properly
again in the next few commits.

Closes: #6717
Fixes: a57f6bc3 ("portal: Clear the environment via flatpak arguments")
2026-07-27 13:51:16 +00:00
Sebastian Wick a6afa04857 repo-utils: Fix double GError set on bundle metadata mismatch
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
2026-07-27 13:41:00 +00:00
Sebastian Wick f6ef98d7bc dir: Fix NULL dereferences with missing metadata
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
2026-07-27 13:41:00 +00:00
Sebastian Wick 5e5e57a807 dir: Fix inverted remote filter cache invalidation
g_file_equal returns TRUE when paths are equal, so the != 0 check
was triggering a reload when the path was unchanged and keeping the
stale cache when the path changed to a different file.
2026-07-27 13:41:00 +00:00
Sebastian Wick eb179c500c dir: Fix NULL dereference in replace_contents_compressed
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2ff1d3b0b3 oci-authenticator: Don't log password in BasicAuthReply handler 2026-07-27 13:41:00 +00:00
Sebastian Wick e222b9351e system-helper: Fix wrong error variable in file monitor warning
The warning for a failed g_file_monitor_file call used error->message
but the error was stored in local_error. If polkit succeeded, error
is NULL, causing a NULL dereference.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2f6fc546ed auth: Return NULL instead of FALSE in pointer-returning function 2026-07-27 13:41:00 +00:00
Sebastian Wick d706ba24a1 system-helper: Validate remote name in deploy and install-bundle
Add the same early remote name validation (reject empty or containing
'/') that other D-Bus handlers already perform, for consistency. The
validation is not required for correctness or security but rejects
obviously invalid input at the entry point.
2026-07-27 13:41:00 +00:00
Sebastian Wick ef91e0900c dir: Handle g_subprocess_new failure in revokefs_fuse_unmount
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
2026-07-27 13:41:00 +00:00
Sebastian Wick 1b1e0609f4 portal: Check for missing instance info in update monitor creation
branch, commit, and app_path are read from the instance info key
file and could be NULL if the keys are missing. This would lead to
NULL dereferences in g_file_new_for_path, g_variant_new_string,
or printf %s. Fail early with an error instead.
2026-07-27 13:41:00 +00:00
Sebastian Wick 398b9c660e repo-utils: Fix typo in summary-history-length config key
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
2026-07-27 13:41:00 +00:00
Sebastian Wick fa794f166c dir: Fix integer overflow in read_fd on 32-bit platforms
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
2026-07-27 13:41:00 +00:00
Sebastian Wick 6950a22bf4 exports: Add recursion depth limit to flatpak_exports_path_get_mode
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
2026-07-27 13:41:00 +00:00
Sebastian Wick e7bdeed3f6 dir: Remove unused force_load parameter from lookup_remote_filter 2026-07-27 13:41:00 +00:00
Sebastian Wick e9c560dd0a dir: Fix return FALSE in pointer-returning dir_create_origin_remote 2026-07-27 13:41:00 +00:00
Sebastian Wick d8c2a2533d system-helper: Fix typo in deploy error message 2026-07-27 13:41:00 +00:00
Sebastian Wick 65623def55 run: Warn on pid file write failure
Both pid file writes silently ignored errors by passing NULL for
the GError. Log a warning so the failure is at least observable.
2026-07-27 13:41:00 +00:00
Sebastian Wick 66967d32b6 oci-registry: Remove unused MAX_JSON_SIZE constant 2026-07-27 13:41:00 +00:00
Sebastian Wick dc1f22ef6d portal: Fix wrong variable in sandbox flags error message
The check tests sandbox_flags but the error message formatted
arg_flags, showing unrelated spawn flags instead of the actual
unsupported sandbox flags.
2026-07-27 13:41:00 +00:00
Sebastian Wick 770047e9eb wayland: Create the socket with SOCK_CLOEXEC and use glnx_autofd 2026-07-27 13:41:00 +00:00
Sebastian Wick 2cedc86f21 wayland: Validate the wayland socket name before using it
If validation failed, we fall back to wayland-0, but we passed the
unvalidated name to flatpak_run_create_wayland_security_context.
2026-07-27 13:41:00 +00:00
Sebastian Wick 4070ef6cb7 context: Consider all conditionals when merging
We would abort when the first conditional was already in the merged set
of conditionals.
2026-07-27 13:41:00 +00:00
Sebastian Wick e9cd846603 context: Fix negated true conditional evaluation logic
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because

    evaluator (condition) == !negated

... and the evaluator evaluates unknown conditions as false.
2026-07-27 13:41:00 +00:00
Sebastian Wick 21f413f17f flatpak-instance: Make constructing failable
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).

Let's just error out as early as possible to avoid those weird
half-initialized cases.

That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
2026-07-27 13:41:00 +00:00
Sebastian Wick 104ed5db5e progress: Clamp to avoid unsigned underflow if fetched exceeds total 2026-07-27 13:41:00 +00:00
Sebastian Wick ab629e27e9 run-sockets: Fix a memory leak in flatpak_run_add_gpg_agent_args 2026-07-27 13:41:00 +00:00
Sebastian Wick dd86b3cf6b enum-types: Explicitly set the enum nick in some cases
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.

Also fix the header guard while at it.

Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
2026-07-27 13:41:00 +00:00
Sebastian Wick a4bea5dca9 run: Add O_CLOEXEC to opening bwrapinfo.json 2026-07-27 13:41:00 +00:00
Sebastian Wick b81414fe98 dir: Handle readlink error in ensure_system_user_cache_dir_location 2026-07-27 13:41:00 +00:00
Sebastian Wick 9dab8f311e repo-utils: Avoid pointing at a illegal location in match_bytes_at_end
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.

This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
2026-07-27 13:41:00 +00:00
Sebastian Wick 380c6b55f8 ref-utils: Fix return type in flatpak_decomposed_new_from_col_ref 2026-07-27 13:41:00 +00:00
Sebastian Wick e12088103a prune: Fix object equality check comparing a to itself
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.
2026-07-27 13:41:00 +00:00
Sebastian Wick 5d5f8e3ea3 installation: Fix return type in fetch_remote_metadata_sync 2026-07-27 13:41:00 +00:00
Sebastian Wick e37e201f3d installation: Ensure error is set on failure in get_min_free_space_bytes 2026-07-27 13:41:00 +00:00
Sebastian Wick 37fe50fc9c installation: Avoid races when caching the display name
We specifically have to avoid holding the lock while calling
flatpak_installation_get_dir_maybe_no_repo, so we just double check if
it is unset.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2a0c49ef89 flatpak-json: Fix strict struct JSON parsing
The code checked the wrong flags. struct_props is the array of child
properties, so struct_props->flags is the flags of the first child
property. What we need to chech is the flags of the current property,
and if it contains FLATPAK_JSON_PROP_FLAGS_STRICT.
2026-07-27 13:41:00 +00:00