Commit Graph
8451 Commits
Author SHA1 Message Date
razzeee cc727e7f09 dir/http: Use gint64 for g_ascii_strtoll return values
g_ascii_strtoll returns gint64; storing the result in a narrower
type (int, gint) silently truncates large values.
2026-05-13 01:08:29 +00:00
razzeee 250516b059 history: Use uid_t and g_ascii_strtoull for UID parsing
UIDs are unsigned; using signed strtoll and int can mishandle
high UIDs such as those used by systemd dynamic users.
2026-05-13 01:08:29 +00:00
Rudi Heitbaum 68ffa487ee dir: fix build when HAVE_LIBSYSTEMD but not USE_SYSTEM_HELPER
polkit_subject_to_string() is called inside the HAVE_LIBSYSTEMD guard
in flatpak_dir_log(), but <polkit/polkit.h> is only included when
USE_SYSTEM_HELPER is defined. This causes a build failure on
configurations that have libsystemd but no system helper.

Guard the polkit call with USE_SYSTEM_HELPER and fall back to "(none)"
so the subject string is always valid for the sd_journal_send() call.

Fixes: f9d5c5c ("dir: Free result of polkit_subject_to_string")
Signed-off-by: Rudi Heitbaum <rudi@heitbaum.com>
2026-05-09 18:56:16 +05:30
Sebastian Wick 3daccaeadc Post-branching version bump 2026-05-06 00:51:17 +02:00
Sebastian Wick b4c53a4cff 1.17.7 1.17.7 2026-05-06 00:48:51 +02:00
Sebastian Wick 8d58ebdeb4 Update translation files for 1.17.7 2026-05-06 00:43:28 +02:00
Sebastian Wick 17cb1135cb context: Keep fallback-x11 separate from x11 conditionals
If we convert fallback-x11 internally to a conditional x11 permission,
we cannot express current fallback-x11 stacking behavior:

lower: empty + upper: !fallback-x11 -> no x11 access
lower: fallback-x11 + upper: !fallback-x11 -> x11 access

The reason is that conditionals have no view of the lower level.

This changes things in a way that fallback-x11 stays its own socket
permission with two interactions with the x11 socket permission:

* If a upper level resets x11 (--socket=x11, --nosocket=x11), the lower
  level fallback-x11 permission gets dropped
* When computing the allowed sockets, --socket=fallback-x11 gets
  converted to --socket=if:x11:!has-wayland

Fixes: #6556
2026-04-29 10:14:29 +00:00
Sebastian Wick bd75302323 tests/repo: Make a test more robust by checking files for diff
Instead of trying to read them into variables, which could fail if there
were null bytes in the key.

Fixes: 43642337 ("dir: Try to delete the remote if we failed to add it entirely")
2026-04-28 13:18:48 +00:00
Sebastian Wick 3296c9e619 system-helper: Fix checking if the reinstall flag was passed in
Fixes: 919d2922 ("common: support reinstall option on bundle installations")
2026-04-28 13:18:48 +00:00
Sebastian Wick 68343e938f tests: Fix checks where we expect a command to fail
I was convinced that the pattern `! command` with -e aborts when
`command` fails. This is not the case (the result of `false` is the same
as `! true` but somehow this doesn't matter).

Fix the tests and use the newly introduced `assert_not` function. One
could also use `command && assert_not_reached "message"` but who has
time to write error messages for all the cases.
2026-04-28 13:18:48 +00:00
razzeee 6dfe1ad4d0 dir: handle missing remote tracking ref in repo_pull so that Flatpak-Upgrade-From header is sent 2026-04-21 11:28:31 +00:00
razzeee fad37dfa8c tests: add test for Flatpak-Upgrade-From header on install vs update
Add an integration test that verifies the Flatpak-Upgrade-From HTTP
header is correctly sent during update operations but absent during
fresh installs. This header is used by Flathub to distinguish updates
from new installs in download statistics.

To support the test, extend web-server.py to optionally log Flatpak-*
request headers to a separate file.
2026-04-21 11:28:31 +00:00
Gordon Messmer fffe38a2b0 common: Report the age of the configuration
This change will allow applications to determine if their data
is older than the flatpak configuration, to aid cache invalidation.
2026-04-20 14:00:20 +00:00
Sebastian Wickandcraftyguy Clayton Craft 43642337e4 dir: Try to delete the remote if we failed to add it entirely
Ideally, we would be able to atomically add and remove remotes, but
we're very far from that ideal state. The current behavior is really
suboptimal and leaves the remotes in a inconsistent state if
initialization failed. We can at least make it better by trying to clean
up the half-initialized mess we're currently in. It does however not
protect against SIGKILL-like aborts, as that would require it to be
atomic.

Closes: #6449
Co-authored-by: craftyguy "Clayton Craft" <clayton@craftyguy.net>
2026-04-20 13:59:14 +00:00
lumingzh 7781da7767 update Chinese translation 2026-04-19 05:35:30 +05:30
Razze 3f2e10e274 tests: add missing assertions after second flatpak_usb_parse_usb_list call
The call to flatpak_usb_parse_usb_list() lacked the
g_assert(ret) and g_assert_no_error(error) guards that are present
on the first call.
2026-04-18 20:33:07 +05:30
emintufan 1ae9b4a4e8 Update Turkish translation 2026-04-18 18:33:04 +05:30
Sebastian Wick 5314d8cf93 dir: Succeed ensure_repo with allow_empty when system helper fails
If _flatpak_dir_ensure_repo is called with allow_empty=true, it is
allowed to fail to create the repo, and is supposed to return success in
that case.

The system helper handles this correctly, but we then call to
ensure_repo_opened no matter if the repo actuall exists and return an
error when it does not, no matter if allow_empty is set or not.

Closes: #6618
2026-04-16 15:24:46 +00:00
Sebastian Wick 3c843932aa tests: Use meson to enumerate the tests
This gets rid of the test-matrix generation, and instead enumerates all
the tests in meson.

Some people (including me) constantly modified the generated meson
instead of the test-matrix generator file because they find it so
uncommon and unusual that a meson file is generated.

This looses the combinatorial combination of the generated system, but
in practice, six lines of enumeration is not bad, and it makes things
easier to understand.
2026-04-16 12:00:46 +00:00
Sebastian Wick e556544833 doc: Document the new has-usb-device and has-usb-portal conditionals 2026-04-16 10:37:45 +00:00
Sebastian Wick 72576c8239 context: Add USB Portal conditional
This can be used by apps to restrict access to `--device=usb` by using
the portal and falling back to `--device=usb` if it is not available:

   --device-if=usb:!has-usb-portal

Closes: #6557
2026-04-16 10:37:45 +00:00
Sebastian Wick b9da5795ed context: Add always-true USB device conditional
This can be used by apps to restrict access from `--device=all` to
`--device=usb` in a backwards compatible way:

   --device-if=all:!has-usb-device --device=usb

Closes: #6557
2026-04-16 10:37:45 +00:00
Cathy Hu 74027a9642 selinux: flatpak.if should be installed in distributed (bsc#1262051)
instead of `contrib`. Otherwise interfaces might clash with the
interfaces from the main policy on fedora and openSUSE.

See the independent policy guideline:
https://fedoraproject.org/wiki/SELinux/IndependentPolicy#Using_custom_interfaces

And:
https://bugzilla.opensuse.org/show_bug.cgi?id=1262051
2026-04-14 13:54:41 +00:00
Sebastian Wick 6fc45b139a portal: Actually use the AppInfo hash table
Before this change, the hash table was populated with the keyfile as key
and value, but the lookup and invalidate was done on the sender as the
key.

We never found a previous sender, and never invalidated one.

Fix this by actually using the sender as the key.
2026-04-13 17:21:33 +00:00
razzeee 655ddb42ec tests: add test-run-custom.sh to test matrix source
test-run-custom.sh was only manually appended to test-matrix/meson.build
and would be lost on regeneration. Add it to update-test-matrix so it is
properly managed.
2026-04-13 16:00:54 +00:00
Sebastian Wick 71034dd024 subprojects: Update dbus-proxy.wrap to v0.1.7
Versions up to 0.1.6 contain a security vulnerability, so let's bump it
to a version which does not.
2026-04-13 17:02:22 +01:00
Simon McVittie 333459c883 dir: Use flatpak_bwrap_child_setup_inherit_fds_cb() to apply extra-data
This is functionally equivalent to the local child_setup() deleted by
this commit, except that it ignores lseek() errors, which can
legitimately happen when inheriting a non-seekable file descriptor.
Since commit ac62ebe "run: Use O_PATH fds for the runtime and app
deploy directories", any extra-data helper that runs inside a runtime
will receive a non-seekable O_PATH fd as its /usr.

Resolves: https://github.com/flatpak/flatpak/issues/6608
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-12 21:47:03 +00:00
Simon McVittie dc9173b2d3 bwrap: Clarify a comment
Now that we're passing the app's /app and /usr down to bwrap as O_PATH
file descriptors, it will be even more common to have non-seekable fds
in the array.

Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-12 21:47:03 +00:00
Razze 51cff37bea tests: fix copy-paste bug checking mid_high instead of highest 2026-04-12 07:37:43 +05:30
Razze 758a096d72 tests: remove duplicate g_mkdir_with_parents call for dont_hide in test_full 2026-04-12 07:25:11 +05:30
Simon McVittie 0337cfde00 subprojects: Ignore .wraplock file generated by recent Meson
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-12 07:23:58 +05:30
Sebastian Wick ed048c91b9 Post-branching version bump 2026-04-10 19:54:10 +02:00
Sebastian Wick 9b21874f1a 1.17.6 1.17.6 2026-04-10 19:51:18 +02:00
Sebastian Wick 1d1d189ada Update translation files for 1.17.6 2026-04-10 19:51:18 +02:00
Sebastian Wick 7776457bfa Post-branching version bump (for 1.17.5 which was forgotten) 2026-04-10 19:50:49 +02:00
razzeee 39dda201c9 tests: fix copy-paste bug using is_arch instead of is_branch in test_decompose 2026-04-10 16:01:35 +00:00
Simon McVittie d42037c526 app, context: Factor out flatpak_accept_fd_argument()
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 16:00:59 +00:00
Simon McVittie c4ab58cd2e app, context: Never close fds 0, 1 or 2
These fds are stdin, stdout and stderr respectively, and are expected
to remain open at all times (if they are not needed then they can point
to /dev/null, but they should always be open). If the user gives us
`--env-fd=2` or similar, we don't want to close fd 2 before exiting
unsuccessfully: that would give us nowhere to display the error message.

Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 16:00:59 +00:00
razzeee f5f70a511e tests: Add messages for missing os-release and pre-create directory checks 2026-04-10 15:52:46 +00:00
razzeee cff9812514 repair: disable auto-pin to preserve pin state across reinstalls
When repair (re)installs runtimes via a transaction, the transaction
auto-pins every runtime it touches. This causes repair --reinstall-all
to pin every installed runtime, cluttering the pin list with runtimes
that were never explicitly pinned by the user and preventing
flatpak remove --unused from cleaning them up.

Fix this by disabling auto-pinning on the repair transaction so that
the pin state is left exactly as it was before the repair.

Fixes https://github.com/flatpak/flatpak/issues/6565
2026-04-10 15:36:00 +00:00
Sebastian Wick 1364527683 tests: Check that flatpak-run fd-arguments do not leak to the command
flatpak-run takes a number of arguments which are file descriptor
numbers. Those file descriptors are supposed to set something up in the
way the instance gets spawned, but should never make it to the wrapper
command.
2026-04-10 14:50:21 +00:00
razzeee 3eadc2c379 tests: remove duplicate g_set_print_handler call in test_format_choices teardown 2026-04-10 14:50:09 +00:00
Simon McVittie 50dda82eb0 libtest: Allow adding a new ref to an existing temporary ostree repo
When we run `tests/test-run-custom.sh` as a build-time test,
we expect to already have the necessary runtimes, apps, etc. in
`${builddir}/tests/runtime-repo`. However, when running "as-installed"
tests, we're using a fresh temporary ostree repo for each test.
Merely having the repo exist is not enough: for some tests, and in
particular `tests/test-run-custom.sh`, it needs to have more than one
runtime available.

Resolves: https://github.com/flatpak/flatpak/issues/6591
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 14:13:39 +00:00
Simon McVittieandSebastian Wick 28634c7f52 portal: Reinstate flatpak_get_path_for_fd() checks
As with the previous commit, historically we would debug-log but
otherwise silently ignore attempts to expose a file in a sandboxed
subsandbox that doesn't have a suitable path.

For example, org.gnome.Epiphany (or possibly WebKitGTK) asks to expose
files from /app and /usr in the subsandbox. When we ignored those
requests (because /app and /usr have a different meaning on the host
system), the app worked as intended anyway, because the subsandbox has
access to the app's /app and the runtime's /usr whether they're
explicitly added or not, so it all worked out OK. However, treating
this as a fatal error (as it arguably should have been) broke
Epiphany's subsandboxes.

Fixes: 3c500145 "portal: Use --bind-fd, --app-fd and --usr-fd options to avoid races"
Resolves: https://github.com/flatpak/flatpak/issues/6584
Co-authored-by: Sebastian Wick <sebastian.wick@redhat.com>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:54:13 +00:00
Simon McVittieandSebastian Wick 75ab6eebb8 portal: Log and ignore unusable sandbox-expose fds instead of erroring
For the sandbox expose fds, a historical quirk of this code is that if
the checks in get_path_for_fd() failed, we would merely log at g_info()
level (usually only shown when debugging the portal), and otherwise
silently ignore the request to expose the fd in the sandbox.

With hindsight this was probably not the right thing to do, but apps
could well be relying on it now. For example, there are indications
that Epiphany might send a memfd from the main instance to a subsandbox,
which never actually worked, but will break that subsandbox process
if that's treated as a fatal error.

Fixes: 3c500145 "portal: Use --bind-fd, --app-fd and --usr-fd options to avoid races"
Helps: https://github.com/flatpak/flatpak/issues/6584
Co-authored-by: Sebastian Wick <sebastian.wick@redhat.com>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:54:13 +00:00
Simon McVittieandSebastian Wick 4ef2421bd2 portal: Avoid crash if sandbox-expose-[ro-]fd is out of range
If the handle is not in the range `0 <= handle < fds_len`, but no
GError is set, we'd have crashed when we dereferenced error->message.
Instead, log an error and early-return, matching what we do for
app-fd, usr-fd and the array of inheritable fds.

Fixes: 3c500145 "portal: Use --bind-fd, --app-fd and --usr-fd options to avoid races"
Helps: https://github.com/flatpak/flatpak/issues/6584
Co-authored-by: Sebastian Wick <sebastian.wick@redhat.com>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:54:13 +00:00
Simon McVittieandSebastian Wick 15dc818874 utils: Move flatpak_get_path_for_fd to here
This was originally in flatpak-portal, then was duplicated into
flatpak-run in commit ac62ebe3 "run: Use O_PATH fds for the runtime and
app deploy directories", and subsequently removed from the portal in
commit 3c500145 "portal: Use --bind-fd, --app-fd and --usr-fd options to
avoid races". Now we want to use it in the portal again.

Helps: https://github.com/flatpak/flatpak/issues/6584
Co-authored-by: Sebastian Wick <sebastian.wick@redhat.com>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:54:13 +00:00
Simon McVittie 0902090726 run, context: Mark fd arguments as close-on-exec
On entry to `flatpak run`, these fds have been inheritable (not
FD_CLOEXEC), otherwise they would not have been inherited; but we don't
want the "payload" command to inherit them, so set them as
non-close-on-exec as soon as we receive them. In the cases where we pass
them down to the underlying bwrap command, we'll either dup them, or
set them to be inheritable again (in practice we dup them).

In particular, Chromium-derived web browsers get very upset when their
subsandbox processes inherit unexpected fds, which has been causing crashes
with no useful diagnostic information since CVE-2026-34078 was fixed.

Fixes: 1b5e886d "run: Add --usr-fd and --app-fd options"
Fixes: b5ae89ed "run: Add --(ro-)bind-fd options"
Resolves: https://github.com/flatpak/flatpak/issues/6582
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:29:58 +00:00
Simon McVittie 8a989c790d utils: Add flatpak_set_cloexec()
Helps: https://github.com/flatpak/flatpak/issues/6582
Signed-off-by: Simon McVittie <smcv@collabora.com>
2026-04-10 12:29:58 +00:00
bbhtt 79cb10e880 tests: Add test for NoRuntime extra-data app 2026-04-10 11:37:40 +00:00