Commit Graph
2756 Commits
Author SHA1 Message Date
Sebastian Wick e04fb5677a ref-utils: Make remote name validation public and take an error
We should be consistent with the validation in the session-helper, so
let's make this validation function available to it.

Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
2026-08-10 23:06:17 +02:00
Simon McVittie d3398edf3e run-dbus: Correct --broadcast rules for the AT-SPI bus
These had the *INTERFACE*.*METHOD* where the bus name should have been,
and a blank interface/method (meaning match any interface/method).
Because there's no bus name of that name on the AT-SPI bus, the only reason
why Flatpak apps were able to receive these broadcasts is that there was
a vulnerability in xdg-dbus-proxy, tracked as GHSA-r7hp-698j-2h6c. To
avoid regressions in Flatpak when the x-d-p vulnerability is fixed,
we need to correct these rules to have the intended bus name.

Signed-off-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
2026-08-10 23:06:17 +02:00
Sebastian Wick 0fc48dd7ab oci: Limit delta path length to PATH_MAX
The previous commit ensures that there isn't a heap overflow when
reading a huge delta path, but we should also just reject unreasonably
long paths. So we chose the arbitrary limit of PATH_MAX and assume that
anything beyond that arbitrary limit is probably abusive.

Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Sebastian Wick 7561bfbe7a oci: Avoid overflow in delta_read_data
delta_read_data computed g_malloc(size + 1) where size came from the
delta stream. If size equals G_MAXSIZE, size + 1 wraps to zero and
g_malloc returns a minimal allocation, then g_input_stream_read_all
writes size bytes into it — a heap buffer overflow.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Sebastian Wick cf1b7255a7 oci: Use gsize for OCI delta sizes
The delta varint parser decoded into guint64 values which were then
passed to GLib I/O and allocation functions that take gsize. On 32-bit
systems where gsize is 32 bits this silently truncated the values.

Change the varint output and all delta operation size parameters to
gsize, and clamp the parsed value to G_MAXSIZE.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
2026-08-10 23:06:17 +02:00
Sebastian Wick 924bdc9b3d run: Harden ensure_data_dir and /var setup against symlink attacks
Replace path-based flatpak_mkdir_p calls in flatpak_ensure_data_dir
with glnx_chase_and_mkdirat(RESOLVE_NO_SYMLINKS) to prevent an app
from replacing subdirectories of its data dir with symlinks between
runs and having them followed during the next sandbox setup.

In flatpak_run_setup_base_argv, replace path-based --bind args for
the app cache/data/config/tmp directories with --bind-fd using fds
obtained via glnx_chaseat(RESOLVE_NO_SYMLINKS), preventing both
symlink following and TOCTOU races when setting up these bind mounts.

Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
2026-08-10 23:06:17 +02:00
Sebastian Wick a9c53b6d4e run: Harden regenerate_ld_cache against symlink attacks
A sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink,
causing regenerate_ld_cache to write files at an arbitrary location.
A concurrent app instance makes this a TOCTOU even after the initial
directory verification.

Replace all path-based operations with fd-based equivalents using
ld_so_dir_fd obtained via glnx_chase_and_mkdirat, and pass the
directory to bwrap via --bind-fd instead of --bind.

Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick 1b9390d398 common: Use fd-based operations in flatpak_switch_symlink_and_remove
Replace path-based syscalls with fd-relative equivalents so callers
can pin the directory identity and prevent symlink substitution by a
concurrent process.

Assisted-by: Claude:opus-4.6
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick a93483828f common: Fix return value and typos in flatpak_switch_symlink_and_remove
One error path returned -1 instead of FALSE. Since gboolean is gint,
-1 is truthy and the caller would skip error handling.

Assisted-by: Claude:opus-4.6
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
2026-08-10 23:06:17 +02:00
Sebastian Wick 8586d3e1e0 Revert "http: Reset curl TLS options between transfers"
This reverts commit 420ce91428.

Apparently we do depend on the session-set certificates in some
situations. We should fix that, but until someone puts in the effort to
do so, reverting this will at least unbreak things.
2026-08-10 20:28:11 +00:00
Sebastian Wick a2900bbe8c appdata: Handle missing component id
A component without an <id> element causes a NULL dereference when
parsing appdata.
2026-08-04 11:38:22 +00:00
Sebastian Wick af0ccc743c dir: Use FLATPAK_ERROR for commit validation failures
The commit metadata and ref validation checks in validate_commit_metadata()
and flatpak_dir_deploy() used G_IO_ERROR which gets downgraded to a generic
G_DBUS_ERROR_FAILED when crossing the system helper D-Bus boundary.
Use FLATPAK_ERROR_PERMISSION_DENIED so the error is preserved across D-Bus.
2026-08-04 11:38:22 +00:00
Sebastian Wick c686880891 image-collection: Guard against NULL manifests
Every other access to index->manifests in the codebase checks for NULL
before dereferencing, but flatpak_image_collection_new did not. Add the
same guard to avoid a NULL pointer dereference if the OCI index has no
manifests array.
2026-08-04 11:38:22 +00:00
Sebastian Wick 4c78990dd3 dir-utils: Fix signed integer overflow in extension priority comparator
The subtraction-based comparison overflows when priority values are far
apart, which is undefined behavior in C.
2026-08-04 11:38:22 +00:00
Sebastian Wick 90dd779443 docker-reference: Validate domain in docker_reference_parse
Instead of just blindly accepting any characters to make up the docker
registry domain, reject invalid domains (including ones which contain
e.g. '@', '#', and '?').
2026-08-04 11:38:22 +00:00
Sebastian Wick 3f41df2556 docker-reference: Don't assert on regex match failure
flatpak_docker_reference_parse() asserts that the regex always matches,
but inputs containing newlines cause the match to fail since the regex
is not compiled with G_REGEX_DOTALL. Return an error instead.
2026-08-04 11:38:22 +00:00
Sebastian Wick 52207faab3 context: Fix conditional permission escalation check
flatpak_permission_adds_permissions() had two bugs in its sorted-array
merge walk for comparing conditional permissions:

The function returned FALSE when a new conditional was not present in
the old set, which is the opposite of correct — a new conditional means
the permission can be granted under conditions it previously could not.

The loop also relied on reading a NULL sentinel past the end of the
GPtrArray, which is not NULL-terminated, causing an out-of-bounds read.

Replace with proper bounds-checked iteration that correctly detects new
conditionals as permission additions.
2026-08-04 11:38:22 +00:00
Sebastian Wick 6dd7825286 chain-input-stream: Close all child streams on close
The close function would bail out on the first child stream close
failure, skipping the remaining children. Close all children and
propagate the first error.
2026-08-04 11:38:22 +00:00
Sebastian Wick 13cf8cfd27 bundle-ref: Use g_clear_pointer for nullable GBytes fields
The metadata, appstream, icon_64, and icon_128 fields are conditionally
initialized in flatpak_bundle_ref_new() depending on which keys exist in
the bundle metadata. The finalize function used g_bytes_unref() which is
not NULL-safe on older GLib versions.
2026-08-04 11:38:22 +00:00
Sebastian Wick 8ce5a4f12a appdata: Don't assert on malformed XML
The appdata XML parser uses g_assert() to validate parser state in
several places. Since the XML comes from the app's deploy directory and
is controlled by the package author, malformed XML triggers abort().

Replace all g_assert() calls with graceful handling: early returns when
there is no current component, NULL checks for content_rating, and
state resets for accumulated text and lang.
2026-08-04 11:38:22 +00:00
Sebastian Wick 56c40cc693 oci-registry: Fix wrong token used in mirror_blob download
flatpak_oci_registry_mirror_blob uses self->token (destination registry)
instead of source_registry->token when downloading from the source. All
other parameters on the same call correctly use source_registry.

In practice the destination is always a local on-disk registry with no
token set, so this results in missing authentication when pulling from
authenticated source registries rather than a credential leak.
2026-08-04 11:38:22 +00:00
Sebastian Wick 41cb4118d1 bwrap: Warn when we failed to add a bind mount 2026-08-04 11:38:22 +00:00
Sebastian Wick f6102c528e context: Add comment to adds_permissions explaining what we do not check 2026-08-04 11:38:22 +00:00
Alexander Vanhee 7777fea6c1 system-helper: Authenticate via polkit for system wide downgrades
Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.

Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
2026-07-27 14:17:06 +00:00
Sebastian Wick a6afa04857 repo-utils: Fix double GError set on bundle metadata mismatch
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
2026-07-27 13:41:00 +00:00
Sebastian Wick f6ef98d7bc dir: Fix NULL dereferences with missing metadata
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
2026-07-27 13:41:00 +00:00
Sebastian Wick 5e5e57a807 dir: Fix inverted remote filter cache invalidation
g_file_equal returns TRUE when paths are equal, so the != 0 check
was triggering a reload when the path was unchanged and keeping the
stale cache when the path changed to a different file.
2026-07-27 13:41:00 +00:00
Sebastian Wick eb179c500c dir: Fix NULL dereference in replace_contents_compressed
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2f6fc546ed auth: Return NULL instead of FALSE in pointer-returning function 2026-07-27 13:41:00 +00:00
Sebastian Wick ef91e0900c dir: Handle g_subprocess_new failure in revokefs_fuse_unmount
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
2026-07-27 13:41:00 +00:00
Sebastian Wick 398b9c660e repo-utils: Fix typo in summary-history-length config key
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
2026-07-27 13:41:00 +00:00
Sebastian Wick fa794f166c dir: Fix integer overflow in read_fd on 32-bit platforms
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
2026-07-27 13:41:00 +00:00
Sebastian Wick 6950a22bf4 exports: Add recursion depth limit to flatpak_exports_path_get_mode
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
2026-07-27 13:41:00 +00:00
Sebastian Wick e7bdeed3f6 dir: Remove unused force_load parameter from lookup_remote_filter 2026-07-27 13:41:00 +00:00
Sebastian Wick e9c560dd0a dir: Fix return FALSE in pointer-returning dir_create_origin_remote 2026-07-27 13:41:00 +00:00
Sebastian Wick 65623def55 run: Warn on pid file write failure
Both pid file writes silently ignored errors by passing NULL for
the GError. Log a warning so the failure is at least observable.
2026-07-27 13:41:00 +00:00
Sebastian Wick 66967d32b6 oci-registry: Remove unused MAX_JSON_SIZE constant 2026-07-27 13:41:00 +00:00
Sebastian Wick 770047e9eb wayland: Create the socket with SOCK_CLOEXEC and use glnx_autofd 2026-07-27 13:41:00 +00:00
Sebastian Wick 2cedc86f21 wayland: Validate the wayland socket name before using it
If validation failed, we fall back to wayland-0, but we passed the
unvalidated name to flatpak_run_create_wayland_security_context.
2026-07-27 13:41:00 +00:00
Sebastian Wick 4070ef6cb7 context: Consider all conditionals when merging
We would abort when the first conditional was already in the merged set
of conditionals.
2026-07-27 13:41:00 +00:00
Sebastian Wick e9cd846603 context: Fix negated true conditional evaluation logic
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because

    evaluator (condition) == !negated

... and the evaluator evaluates unknown conditions as false.
2026-07-27 13:41:00 +00:00
Sebastian Wick 21f413f17f flatpak-instance: Make constructing failable
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).

Let's just error out as early as possible to avoid those weird
half-initialized cases.

That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
2026-07-27 13:41:00 +00:00
Sebastian Wick 104ed5db5e progress: Clamp to avoid unsigned underflow if fetched exceeds total 2026-07-27 13:41:00 +00:00
Sebastian Wick ab629e27e9 run-sockets: Fix a memory leak in flatpak_run_add_gpg_agent_args 2026-07-27 13:41:00 +00:00
Sebastian Wick dd86b3cf6b enum-types: Explicitly set the enum nick in some cases
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.

Also fix the header guard while at it.

Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
2026-07-27 13:41:00 +00:00
Sebastian Wick a4bea5dca9 run: Add O_CLOEXEC to opening bwrapinfo.json 2026-07-27 13:41:00 +00:00
Sebastian Wick b81414fe98 dir: Handle readlink error in ensure_system_user_cache_dir_location 2026-07-27 13:41:00 +00:00
Sebastian Wick 9dab8f311e repo-utils: Avoid pointing at a illegal location in match_bytes_at_end
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.

This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
2026-07-27 13:41:00 +00:00
Sebastian Wick 380c6b55f8 ref-utils: Fix return type in flatpak_decomposed_new_from_col_ref 2026-07-27 13:41:00 +00:00
Sebastian Wick e12088103a prune: Fix object equality check comparing a to itself
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.
2026-07-27 13:41:00 +00:00