Commit Graph
8623 Commits
Author SHA1 Message Date
Sebastian Wick aa19390539 revokefs: Avoid symlink path traversal in chmod()
Use glnx_chaseat to ensure that all the attacker-controlled paths end up
inside the basefd directory, and then AT_SYMLINK_NOFOLLOW to make sure
that the last path component won't escape from the basefd.

On kernels >= 6.6 we can now use fchmodat() with AT_SYMLINK_NOFOLLOW,
but on older kernels that didn't work, so if necessary fall back to
opening the file with O_NOFOLLOW and then calling fchmod() on it.

Because this is the last syscall that used the previous (flawed)
validation mechanism, we can now remove the validation helpers and be
sure that everything is using the glnx-chaseat()-based replacements.

[smcv: Separated from a larger commit for better reviewability]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
2026-08-10 23:06:17 +02:00
Sebastian Wick c68be6274e revokefs: Avoid symlink path traversal in symlink()
Use glnx_chaseat to ensure that the attacker-controlled symlink name
ends up inside the basefd directory. Note that the symlink *target* is
also attacker-controlled, but it's OK for them to be able to set any
target of their choice: that can't immediately cause traversal outside
the base directory.

[smcv: Separated from a larger commit for better reviewability]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
2026-08-10 23:06:17 +02:00
Sebastian Wick 8ec442db82 revokefs: Avoid symlink path traversal in link(), rename()
Again, use glnx_chaseat to ensure that all the attacker-controlled paths
end up inside the basefd directory. These two syscalls are a bit more
complicated, and take two paths.

[smcv: Separated from a larger commit for better reviewability]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
2026-08-10 23:06:17 +02:00
Sebastian Wick 8156c75d2b revokefs: Avoid symlink path traversal out of basefd in simple cases
Use glnx_chaseat to ensure that all the attacker-controlled paths end up
inside the basefd directory.

This requires some new helper functions, which will be used in more
complicated syscalls' implementations in subsequent commits.

[smcv: Separated from a larger commit for better reviewability]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
2026-08-10 23:06:17 +02:00
Simon McVittie 12b79e1b11 tests: Add some unit tests for ref-utils name component validation
In the fix for GHSA-v2gw-v9h5-9q4x these functions are used to avoid
path traversal, so we'd better assert that they do detect and avoid it.

Signed-off-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
2026-08-10 23:06:17 +02:00
Sebastian Wick c7492da6b4 system-helper: Validate each remote name and architecture argument
We pass them on to internal functions which assume that they are valid,
and specifically also create paths which contain those strings which can
be used for path traversal attacks.

Let's simply consistently validate all of those arguments.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
2026-08-10 23:06:17 +02:00
Sebastian Wick e04fb5677a ref-utils: Make remote name validation public and take an error
We should be consistent with the validation in the session-helper, so
let's make this validation function available to it.

Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
2026-08-10 23:06:17 +02:00
Simon McVittie d3398edf3e run-dbus: Correct --broadcast rules for the AT-SPI bus
These had the *INTERFACE*.*METHOD* where the bus name should have been,
and a blank interface/method (meaning match any interface/method).
Because there's no bus name of that name on the AT-SPI bus, the only reason
why Flatpak apps were able to receive these broadcasts is that there was
a vulnerability in xdg-dbus-proxy, tracked as GHSA-r7hp-698j-2h6c. To
avoid regressions in Flatpak when the x-d-p vulnerability is fixed,
we need to correct these rules to have the intended bus name.

Signed-off-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
2026-08-10 23:06:17 +02:00
Sebastian Wick 0fc48dd7ab oci: Limit delta path length to PATH_MAX
The previous commit ensures that there isn't a heap overflow when
reading a huge delta path, but we should also just reject unreasonably
long paths. So we chose the arbitrary limit of PATH_MAX and assume that
anything beyond that arbitrary limit is probably abusive.

Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Sebastian Wick 7561bfbe7a oci: Avoid overflow in delta_read_data
delta_read_data computed g_malloc(size + 1) where size came from the
delta stream. If size equals G_MAXSIZE, size + 1 wraps to zero and
g_malloc returns a minimal allocation, then g_input_stream_read_all
writes size bytes into it — a heap buffer overflow.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Sebastian Wick cf1b7255a7 oci: Use gsize for OCI delta sizes
The delta varint parser decoded into guint64 values which were then
passed to GLib I/O and allocation functions that take gsize. On 32-bit
systems where gsize is 32 bits this silently truncated the values.

Change the varint output and all delta operation size parameters to
gsize, and clamp the parsed value to G_MAXSIZE.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Simon McVittie 4fd1d67479 tests: Add a regression test for GHSA-8688-9x26-hhxj
The original reporter used various tricks to find a way for the sandboxed
app to overwrite these locations with symlinks, but for the purposes
of this test, I'm doing the setup outside the sandbox instead: probably
not all of these potential exploit routes are actually possible, but we
defend against all of them symmetrically.

Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-08-10 23:06:17 +02:00
Sebastian Wick 924bdc9b3d run: Harden ensure_data_dir and /var setup against symlink attacks
Replace path-based flatpak_mkdir_p calls in flatpak_ensure_data_dir
with glnx_chase_and_mkdirat(RESOLVE_NO_SYMLINKS) to prevent an app
from replacing subdirectories of its data dir with symlinks between
runs and having them followed during the next sandbox setup.

In flatpak_run_setup_base_argv, replace path-based --bind args for
the app cache/data/config/tmp directories with --bind-fd using fds
obtained via glnx_chaseat(RESOLVE_NO_SYMLINKS), preventing both
symlink following and TOCTOU races when setting up these bind mounts.

Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
2026-08-10 23:06:17 +02:00
Simon McVittie 2beb8890dc test-run: Check that the way com.valvesoftware.Steam behaves still works
This use of symlinks to ensure that the canonicalized paths of
`$XDG_CACHE_HOME`, `$XDG_CONFIG_HOME`, `$XDG_DATA_HOME` are
`~/.cache`, `~/.config`, `~/.local/share` is the sort of thing that
could easily regress if not tested.

Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-08-10 23:06:17 +02:00
Sebastian Wick a9c53b6d4e run: Harden regenerate_ld_cache against symlink attacks
A sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink,
causing regenerate_ld_cache to write files at an arbitrary location.
A concurrent app instance makes this a TOCTOU even after the initial
directory verification.

Replace all path-based operations with fd-based equivalents using
ld_so_dir_fd obtained via glnx_chase_and_mkdirat, and pass the
directory to bwrap via --bind-fd instead of --bind.

Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick 1b9390d398 common: Use fd-based operations in flatpak_switch_symlink_and_remove
Replace path-based syscalls with fd-relative equivalents so callers
can pin the directory identity and prevent symlink substitution by a
concurrent process.

Assisted-by: Claude:opus-4.6
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick a93483828f common: Fix return value and typos in flatpak_switch_symlink_and_remove
One error path returned -1 instead of FALSE. Since gboolean is gint,
-1 is truthy and the caller would skip error handling.

Assisted-by: Claude:opus-4.6
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick 8586d3e1e0 Revert "http: Reset curl TLS options between transfers"
This reverts commit 420ce91428.

Apparently we do depend on the session-set certificates in some
situations. We should fix that, but until someone puts in the effort to
do so, reverting this will at least unbreak things.
2026-08-10 20:28:11 +00:00
Sebastian Wick 0baf60c3a1 session-helper: Lock runtime directory to prevent tmpfiles cleanup
systemd-tmpfiles can be configured to periodically cleans /run/user,
which can remove the session helper's p11-kit socket. Once removed, all
subsequent Flatpak launches fail with "Can't find source path" until the
session helper restarts.

Take a shared flock on the .flatpak-helper directory for the lifetime
of the process. systemd-tmpfiles --clean skips directories that are
locked.

Helps: https://github.com/flatpak/flatpak/issues/6341
2026-08-07 15:18:05 +00:00
Genesis 1e1e6f42f4 docs: add ostree to Fedora build dependencies
`dnf builddep flatpak` only installs `ostree-devel` and `ostree-libs`.
The standalone `/usr/bin/ostree` binary was trimmed out in 2017. Add `ostree` explicitly to `CONTRIBUTING.md`.
2026-08-05 17:47:36 -05:00
Mia McMahill 5ba8afd1be completion: Add bash completion for flatpak-coredumpctl
completion: Use readarray for splitting output
2026-08-05 15:12:03 +00:00
lumingzh 8834a80b41 update zh_CN.po 2026-08-05 15:04:26 +00:00
Rafael Fontenelle 1d4be1123a Update Brazilian Portuguese translation 2026-08-05 15:04:12 +00:00
Sebastian Wick a2900bbe8c appdata: Handle missing component id
A component without an <id> element causes a NULL dereference when
parsing appdata.
2026-08-04 11:38:22 +00:00
Sebastian Wick af0ccc743c dir: Use FLATPAK_ERROR for commit validation failures
The commit metadata and ref validation checks in validate_commit_metadata()
and flatpak_dir_deploy() used G_IO_ERROR which gets downgraded to a generic
G_DBUS_ERROR_FAILED when crossing the system helper D-Bus boundary.
Use FLATPAK_ERROR_PERMISSION_DENIED so the error is preserved across D-Bus.
2026-08-04 11:38:22 +00:00
Sebastian Wick c686880891 image-collection: Guard against NULL manifests
Every other access to index->manifests in the codebase checks for NULL
before dereferencing, but flatpak_image_collection_new did not. Add the
same guard to avoid a NULL pointer dereference if the OCI index has no
manifests array.
2026-08-04 11:38:22 +00:00
Sebastian Wick 4c78990dd3 dir-utils: Fix signed integer overflow in extension priority comparator
The subtraction-based comparison overflows when priority values are far
apart, which is undefined behavior in C.
2026-08-04 11:38:22 +00:00
Sebastian Wick 90dd779443 docker-reference: Validate domain in docker_reference_parse
Instead of just blindly accepting any characters to make up the docker
registry domain, reject invalid domains (including ones which contain
e.g. '@', '#', and '?').
2026-08-04 11:38:22 +00:00
Sebastian Wick 3f41df2556 docker-reference: Don't assert on regex match failure
flatpak_docker_reference_parse() asserts that the regex always matches,
but inputs containing newlines cause the match to fail since the regex
is not compiled with G_REGEX_DOTALL. Return an error instead.
2026-08-04 11:38:22 +00:00
Sebastian Wick 52207faab3 context: Fix conditional permission escalation check
flatpak_permission_adds_permissions() had two bugs in its sorted-array
merge walk for comparing conditional permissions:

The function returned FALSE when a new conditional was not present in
the old set, which is the opposite of correct — a new conditional means
the permission can be granted under conditions it previously could not.

The loop also relied on reading a NULL sentinel past the end of the
GPtrArray, which is not NULL-terminated, causing an out-of-bounds read.

Replace with proper bounds-checked iteration that correctly detects new
conditionals as permission additions.
2026-08-04 11:38:22 +00:00
Sebastian Wick 6dd7825286 chain-input-stream: Close all child streams on close
The close function would bail out on the first child stream close
failure, skipping the remaining children. Close all children and
propagate the first error.
2026-08-04 11:38:22 +00:00
Sebastian Wick 13cf8cfd27 bundle-ref: Use g_clear_pointer for nullable GBytes fields
The metadata, appstream, icon_64, and icon_128 fields are conditionally
initialized in flatpak_bundle_ref_new() depending on which keys exist in
the bundle metadata. The finalize function used g_bytes_unref() which is
not NULL-safe on older GLib versions.
2026-08-04 11:38:22 +00:00
Sebastian Wick 8ce5a4f12a appdata: Don't assert on malformed XML
The appdata XML parser uses g_assert() to validate parser state in
several places. Since the XML comes from the app's deploy directory and
is controlled by the package author, malformed XML triggers abort().

Replace all g_assert() calls with graceful handling: early returns when
there is no current component, NULL checks for content_rating, and
state resets for accumulated text and lang.
2026-08-04 11:38:22 +00:00
Sebastian Wick 56c40cc693 oci-registry: Fix wrong token used in mirror_blob download
flatpak_oci_registry_mirror_blob uses self->token (destination registry)
instead of source_registry->token when downloading from the source. All
other parameters on the same call correctly use source_registry.

In practice the destination is always a local on-disk registry with no
token set, so this results in missing authentication when pulling from
authenticated source registries rather than a credential leak.
2026-08-04 11:38:22 +00:00
Sebastian Wick 660d3dfcfd system-helper: Validate ref in RemoveLocalRef
handle_remove_local_ref validates the remote name but passes the ref
string directly to flatpak_dir_remove_ref without validation. Since the
polkit action for this method is modify-repo (allow_active=yes), any
active session user can delete arbitrary ostree refs in the system repo
without authentication.

All legitimate callers of RemoveLocalRef pass standard flatpak refs
(app/runtime). Non-standard refs like appstream/, appstream2/, and
ostree-metadata are managed through their own dedicated D-Bus methods
(DeployAppstream, UpdateRemote, ConfigureRemote) and never go through
RemoveLocalRef.

Validate the ref with flatpak_decomposed_new_from_ref() to restrict
removal to valid flatpak refs.
2026-08-04 11:38:22 +00:00
Sebastian Wick 52be0a8a9a system-helper: Ensure deploy authorization matches operation
The Deploy authorization handler decides between app-install (requires
admin auth) and app-update (no auth needed) by checking whether the ref
is currently installed. The deploy handler then independently checks the
deployed state to decide whether to install or update.

Record the authorization decision on the invocation and verify in the
deploy handler that the operation matches what was authorized.
2026-08-04 11:38:22 +00:00
Sebastian Wick 6b7872d7ed system-helper: Drop supplementary groups
In case something takes over the process, not having any supplementary
groups limits the damage that can be done.
2026-08-04 11:38:22 +00:00
Sebastian Wick 41cb4118d1 bwrap: Warn when we failed to add a bind mount 2026-08-04 11:38:22 +00:00
Sebastian Wick f6102c528e context: Add comment to adds_permissions explaining what we do not check 2026-08-04 11:38:22 +00:00
Anders Jonsson cea48f27d2 Update Swedish translation 2026-08-03 11:15:19 +00:00
Luigi Pavan 0717cd1685 cli: Don't set no_interaction for --assumeyes
The --assumeyes (-y) option was setting both the CLI-level
disable_interaction flag and the library-level no_interaction flag to
TRUE. This caused -y to suppress not just confirmation prompts, but
also credential prompts (basic auth, webflow), polkit authorization
dialogs, and parental control consent -- even though -y is documented
as "automatically answer yes to all questions".

Rename disable_interaction to assume_yes to clarify its purpose: it
auto-answers yes/no confirmations and picks default choices. Stop
calling flatpak_transaction_set_no_interaction() from the CLI
transaction constructor, so the library-level no_interaction flag is
only set by --noninteractive (which uses FlatpakQuietTransaction).
Remove the assume_yes guard from basic_auth_start so credential
prompts are always shown when the CLI transaction is in use.

Assisted-by: Cursor
2026-07-29 09:42:26 +00:00
Philip Withnall da47d3b236 tests: Prevent gcov warnings spuriously failing test-history.sh
If flatpak is built with code coverage enabled, libgcov sometimes
helpfully emits messages in the output from programs under test.

If we’re strictly comparing the whole output of a program to an expected
string, as `test-history.sh` does in these two places, this can cause
spurious test failures.

Temporarily tell it to send its error messages to `/dev/null` as we
don’t care about them for those tests.

Signed-off-by: Philip Withnall <pwithnall@gnome.org>
2026-07-27 18:55:32 +00:00
Alexander Vanhee 7777fea6c1 system-helper: Authenticate via polkit for system wide downgrades
Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.

Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
2026-07-27 14:17:06 +00:00
Sebastian Wick d82c247cde portal: Test that the different envs get created as expected
Assisted-by: Claude:opus-4.6
2026-07-27 13:51:16 +00:00
Sebastian Wick 21a9692718 portal: Cleanup getting the host-like environment for flatpak-run 2026-07-27 13:51:16 +00:00
Sebastian Wick afbabdc32c portal: Pass run-environ to the spawned flatpak process, not the sandbox
Instead of modifying the host-like run environment to clear the sandbox
environment, we'll use the new --clear-env flag which does the correct
thing.

Assisted-by: Claude:opus-4.6
Closes: #5271
2026-07-27 13:51:16 +00:00
Sebastian Wick 7322a05c7f portal: Clear error after warning to avoid issues on the next error 2026-07-27 13:51:16 +00:00
Sebastian Wick b9fb6d4e25 Revert "portal: Clear the environment via flatpak arguments"
This reverts commit a57f6bc372.

The run-environ from the calling instance is a host-like environment
(e.g. on NixOS it contains /nix/store paths). Passing it via --env
injects it into the sandbox payload environment where those paths don't
exist.

Revert the commit, so we pass run-environ as the envp for spawning
flatpak run again to let it make host-level decisions (DISPLAY,
FLATPAK_GL_DRIVERS, XDG_RUNTIME_DIR, etc.) without leaking into the
sandbox.

It also passes --clear-env unconditionally, because we'd build up the
environment, but the wrong one. We will implement --clear-env properly
again in the next few commits.

Closes: #6717
Fixes: a57f6bc3 ("portal: Clear the environment via flatpak arguments")
2026-07-27 13:51:16 +00:00
Sebastian Wick a6afa04857 repo-utils: Fix double GError set on bundle metadata mismatch
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
2026-07-27 13:41:00 +00:00
Sebastian Wick f6ef98d7bc dir: Fix NULL dereferences with missing metadata
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
2026-07-27 13:41:00 +00:00