Instead of modifying the host-like run environment to clear the sandbox
environment, we'll use the new --clear-env flag which does the correct
thing.
Assisted-by: Claude:opus-4.6
Closes: #5271
This reverts commit a57f6bc372.
The run-environ from the calling instance is a host-like environment
(e.g. on NixOS it contains /nix/store paths). Passing it via --env
injects it into the sandbox payload environment where those paths don't
exist.
Revert the commit, so we pass run-environ as the envp for spawning
flatpak run again to let it make host-level decisions (DISPLAY,
FLATPAK_GL_DRIVERS, XDG_RUNTIME_DIR, etc.) without leaking into the
sandbox.
It also passes --clear-env unconditionally, because we'd build up the
environment, but the wrong one. We will implement --clear-env properly
again in the next few commits.
Closes: #6717
Fixes: a57f6bc3 ("portal: Clear the environment via flatpak arguments")
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
g_file_equal returns TRUE when paths are equal, so the != 0 check
was triggering a reload when the path was unchanged and keeping the
stale cache when the path changed to a different file.
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
The warning for a failed g_file_monitor_file call used error->message
but the error was stored in local_error. If polkit succeeded, error
is NULL, causing a NULL dereference.
Add the same early remote name validation (reject empty or containing
'/') that other D-Bus handlers already perform, for consistency. The
validation is not required for correctness or security but rejects
obviously invalid input at the entry point.
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
branch, commit, and app_path are read from the instance info key
file and could be NULL if the keys are missing. This would lead to
NULL dereferences in g_file_new_for_path, g_variant_new_string,
or printf %s. Fail early with an error instead.
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
The check tests sandbox_flags but the error message formatted
arg_flags, showing unrelated spawn flags instead of the actual
unsupported sandbox flags.
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because
evaluator (condition) == !negated
... and the evaluator evaluates unknown conditions as false.
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).
Let's just error out as early as possible to avoid those weird
half-initialized cases.
That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.
Also fix the header guard while at it.
Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.
This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.
The code checked the wrong flags. struct_props is the array of child
properties, so struct_props->flags is the flags of the first child
property. What we need to chech is the flags of the current property,
and if it contains FLATPAK_JSON_PROP_FLAGS_STRICT.
Copy and paste error which results in the default and explicit usage of
--clear-env to be inverted.
Fixes: f760f1b5 ("run: Add --clear-env option for clearing the outside environment")
It was accidentally parsed into the product union member but because it
has the same layout as the vendor one, this didn't turn into a bug in
practice, but it probably is UB.