Commit Graph
2729 Commits
Author SHA1 Message Date
Sebastian Wick eb179c500c dir: Fix NULL dereference in replace_contents_compressed
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2f6fc546ed auth: Return NULL instead of FALSE in pointer-returning function 2026-07-27 13:41:00 +00:00
Sebastian Wick ef91e0900c dir: Handle g_subprocess_new failure in revokefs_fuse_unmount
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
2026-07-27 13:41:00 +00:00
Sebastian Wick 398b9c660e repo-utils: Fix typo in summary-history-length config key
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
2026-07-27 13:41:00 +00:00
Sebastian Wick fa794f166c dir: Fix integer overflow in read_fd on 32-bit platforms
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
2026-07-27 13:41:00 +00:00
Sebastian Wick 6950a22bf4 exports: Add recursion depth limit to flatpak_exports_path_get_mode
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
2026-07-27 13:41:00 +00:00
Sebastian Wick e7bdeed3f6 dir: Remove unused force_load parameter from lookup_remote_filter 2026-07-27 13:41:00 +00:00
Sebastian Wick e9c560dd0a dir: Fix return FALSE in pointer-returning dir_create_origin_remote 2026-07-27 13:41:00 +00:00
Sebastian Wick 65623def55 run: Warn on pid file write failure
Both pid file writes silently ignored errors by passing NULL for
the GError. Log a warning so the failure is at least observable.
2026-07-27 13:41:00 +00:00
Sebastian Wick 66967d32b6 oci-registry: Remove unused MAX_JSON_SIZE constant 2026-07-27 13:41:00 +00:00
Sebastian Wick 770047e9eb wayland: Create the socket with SOCK_CLOEXEC and use glnx_autofd 2026-07-27 13:41:00 +00:00
Sebastian Wick 2cedc86f21 wayland: Validate the wayland socket name before using it
If validation failed, we fall back to wayland-0, but we passed the
unvalidated name to flatpak_run_create_wayland_security_context.
2026-07-27 13:41:00 +00:00
Sebastian Wick 4070ef6cb7 context: Consider all conditionals when merging
We would abort when the first conditional was already in the merged set
of conditionals.
2026-07-27 13:41:00 +00:00
Sebastian Wick e9cd846603 context: Fix negated true conditional evaluation logic
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because

    evaluator (condition) == !negated

... and the evaluator evaluates unknown conditions as false.
2026-07-27 13:41:00 +00:00
Sebastian Wick 21f413f17f flatpak-instance: Make constructing failable
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).

Let's just error out as early as possible to avoid those weird
half-initialized cases.

That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
2026-07-27 13:41:00 +00:00
Sebastian Wick 104ed5db5e progress: Clamp to avoid unsigned underflow if fetched exceeds total 2026-07-27 13:41:00 +00:00
Sebastian Wick ab629e27e9 run-sockets: Fix a memory leak in flatpak_run_add_gpg_agent_args 2026-07-27 13:41:00 +00:00
Sebastian Wick dd86b3cf6b enum-types: Explicitly set the enum nick in some cases
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.

Also fix the header guard while at it.

Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
2026-07-27 13:41:00 +00:00
Sebastian Wick a4bea5dca9 run: Add O_CLOEXEC to opening bwrapinfo.json 2026-07-27 13:41:00 +00:00
Sebastian Wick b81414fe98 dir: Handle readlink error in ensure_system_user_cache_dir_location 2026-07-27 13:41:00 +00:00
Sebastian Wick 9dab8f311e repo-utils: Avoid pointing at a illegal location in match_bytes_at_end
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.

This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
2026-07-27 13:41:00 +00:00
Sebastian Wick 380c6b55f8 ref-utils: Fix return type in flatpak_decomposed_new_from_col_ref 2026-07-27 13:41:00 +00:00
Sebastian Wick e12088103a prune: Fix object equality check comparing a to itself
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.
2026-07-27 13:41:00 +00:00
Sebastian Wick 5d5f8e3ea3 installation: Fix return type in fetch_remote_metadata_sync 2026-07-27 13:41:00 +00:00
Sebastian Wick e37e201f3d installation: Ensure error is set on failure in get_min_free_space_bytes 2026-07-27 13:41:00 +00:00
Sebastian Wick 37fe50fc9c installation: Avoid races when caching the display name
We specifically have to avoid holding the lock while calling
flatpak_installation_get_dir_maybe_no_repo, so we just double check if
it is unset.
2026-07-27 13:41:00 +00:00
Sebastian Wick 2a0c49ef89 flatpak-json: Fix strict struct JSON parsing
The code checked the wrong flags. struct_props is the array of child
properties, so struct_props->flags is the flags of the first child
property. What we need to chech is the flags of the current property,
and if it contains FLATPAK_JSON_PROP_FLAGS_STRICT.
2026-07-27 13:41:00 +00:00
Sebastian Wick c4d12fa6ad zstd-compressor: Abort on ZSTD_initCStream error
This doesn't seem to happen in practice, but the API says it's possible,
so we better abort than run into weird states.
2026-07-27 13:41:00 +00:00
Sebastian Wick a68d120bc1 image-source: Handle NULL commit subjects and bodies 2026-07-27 13:41:00 +00:00
Sebastian Wick 1825293e27 run: Add error handling for g_unix_fd_list_append
It also adds autofd cleanup and simplifies the control flow a bit.
2026-07-27 13:41:00 +00:00
Sebastian Wick 59ef3bc49a usb: Parse the vnd rule into the vendor union member
It was accidentally parsed into the product union member but because it
has the same layout as the vendor one, this didn't turn into a bug in
practice, but it probably is UB.
2026-07-27 13:41:00 +00:00
Sebastian Wick e881563fd4 remote-ref: Fix the get_property of the download-size property 2026-07-27 13:41:00 +00:00
Sebastian Wick 027cd64af0 xml-utils: Escape XML attribute values when serializing 2026-07-27 13:41:00 +00:00
Sebastian Wick 7ecf90f1dd json-oci: Clean up dead code in flatpak_oci_index_get_manifest_for_arch 2026-07-27 13:41:00 +00:00
Sebastian Wick d2f364bbd7 locale-utils: Ensure the flatpak lang only contains a-zA-Z
This should be the case anyway right now and makes it easier to ensure
the code using it is correct.
2026-07-27 13:41:00 +00:00
Sebastian Wick c771d52887 dir-utils: Fix return type in flatpak_find_current_ref 2026-07-27 13:41:00 +00:00
Maximiliano Sandoval 59f9a7729f common: Stop using G_GNUC_CONST in _get_type funcs
As per g_type_ensure's documentation it is technically incorrect to mark
_get_type fns with G_GNUC_CONST since they have side-effects on their
first run.

See https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5223 for more
details.
2026-07-06 08:23:01 +00:00
John Cardullo f266346d6d run: Validate file object before checking cached path
Verify that the file object is valid before checking its cached path
to avoid a potential NULL pointer dereference.

Fixes: c4fce9e4 ("run: Error out if file forwarding of empty paths is attempted")
2026-07-03 17:16:06 +00:00
razzeee 4006907ba3 transaction: Add flatpak_transaction_progress_get_bytes_per_second() 2026-06-23 09:50:04 +00:00
bbhtt 5fcf748ac9 dir: Don't pass temp repo path to flatpak_dir_log during initial pull
During a system install with the system helper enabled, the initial
network pull goes to a temporary repo and then via pull local from that
repo to the final system repo while during user install there is only
one pull from network to the final repo.

c672c55 set the logger to use the temporary repo path as installation
but the history command afc87ad since the same day filters the initial
pull out as the installation name will never match the temporary path.

This causes the initial pull operation to be never show up in flatpak
history when using system installs while they work for user installs as
`INSTALLATION=user`.

This is presumably also broken for custom installations as they
will similarly not match the temp repo path.

So don't pass the path at all to flatpak_dir_log and we can later
fall back via flatpak_dir_get_name_cached() which sets the correct
`INSTALLATION` for system installs ie. `INSTALLATION=system`.

This also allows us to remove the workaround of adding two different
expected history outputs from ad1ff6d as both branches log the pull.

Without system helper `flatpak install` needs to be executed as
priviledged to operate on system install so the initial pull was
always logged correctly for that branch.
2026-06-23 09:11:59 +00:00
bbhtt f4946b206b flatpak-context: Add test for flatpak_permission_to_args negated output
Test for the bug fixed in db70882d. We test no(socket | device) anyway
to stop future regressions.
2026-06-23 08:46:20 +00:00
Sebastian Wick c4fce9e42a run: Error out if file forwarding of empty paths is attempted
The file forwarding feature errors out when the path or URI does not
lead to an actual file that can be forwarded. The empty path never
describes an actual file, so we always have to error out.

Without the check, we would get a NULL path from
`flatpak_file_get_path_cached` and crash later.

Closes: #6689
2026-06-23 08:44:34 +00:00
Owen W. Taylor 906affa13b Handle null properties as missing properties
We were handling null properties the same as missing properties
*except* that the MANDATORY flag allowed null properties but
not missing properties. Fix this, so null is disallowed by
MANDATORY.

When checking signatures, the image identity could only have
been NULL if it was null in the input file - so replace a
conditional check on it being non-null with an assertion.
2026-06-16 20:13:10 +00:00
Owen W. Taylor b15828e119 Fix crash on image indexes with missing architecture
It's legitimate to have manifests listed in an image index that
have no platform object, and hence no architecture - avoid crashing
if we encounter such a manifest.
2026-06-16 20:13:10 +00:00
Owen W. Taylor fa4b413c02 Make mandatory properties from OCI specifications mandatory
Mark all properties required by the OCI specification as required;
this eliminates a bunch of cases where we were assuming that
descriptor->digest was non-NULL, and potentially generating
critical errors from g_return_if_fail().
2026-06-16 20:13:10 +00:00
Mia McMahill 4d3f0bbb79 app, common: Remove duplicate directories from export functions
Both collect exports and flatpak_export_dir recursively export the
directories in their respective directory lists. Because of this,
including share/metainfo/releases when share/metainfo is already in the
lists is unnecessary and can cause exporting to fail because of
duplicate files.
2026-06-16 11:20:58 +00:00
Kolja Lampe 4ff158caea http: Propagate stream write failures to curl
We did not report the written bytes of the aborted stream before - so
curl thought that we wrote all bytes.
2026-06-15 10:02:12 +00:00
Kolja Lampe 420ce91428 http: Reset curl TLS options between transfers
Previously the curl object potentially leaked cert infos from different
urls
2026-06-15 10:02:12 +00:00
Razze 8ac2adefce oci-registry: Apply TLS certs to request
Signature downloads can use a different URL from the OCI registry
itself, so they must not depend on TLS options left on the reused curl
handle. Resolve certificates for the URI and pass them explicitly.
2026-06-15 10:02:12 +00:00
bbhtt 69bf837676 instance: Annotate flatpak_instance_get_all as (transfer container)
Annotating the return as (transfer full) causes bindings to additionally
unref each element on array free, resulting in a use-after-free.

Change the annotation to (transfer container) so bindings know to unref
the array only.

Fixes: https://github.com/flatpak/flatpak/issues/6666
2026-06-15 09:26:10 +00:00