mirror of
https://github.com/flatpak/flatpak.git
synced 2026-09-12 22:22:09 -04:00
0860bb1d70bac4e8ab1041a329bc07d986061dc8
apply_extra_data() used GFile path-based operations that follow symlinks: --ro-bind/--bind with resolved paths, chmod on the extra directory path, and flatpak_cp_a for the extra/export merge. These are not independently exploitable: apply_extra_data only runs after extract_extra_data has already created files/extra as a real directory, so there is no symlink left to follow. The apply_extra script itself runs in a restricted sandbox with dropped caps and no /proc. The extra/export merge only adds to the app's own export directory, which is already app-controlled and whose desktop file Exec keys are rewritten to flatpak run. Replace with fd-relative operations as defense in depth: glnx_chaseat with GLNX_CHASE_RESOLVE_NO_SYMLINKS and GLNX_CHASE_RESOLVE_BENEATH for directory traversal, --ro-bind-fd/--bind-fd for bwrap mounts, fchmod on the directory fd, and flatpak_cp_a_at for the export merge. Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg [smcv: Use glnx_fd_reopen() to reopen O_PATH fd as readable] Co-authored-by: Simon McVittie <smcv@collabora.com>
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
See https://flatpak.org/ for more information.
Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.
Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.
Read documentation for Flatpak here.
Contributing
Flatpak welcomes contributions from anyone! Here are some ways you can help:
- Fix one of the issues and submit a PR
- Update flatpak's translations and submit a PR
- Improve flatpak's documentation, hosted at http://docs.flatpak.org and developed over in flatpak-docs
- Find a bug and submit a detailed report including your OS, flatpak version, and the steps to reproduce
- Add your favorite application to Flathub by writing a flatpak-builder manifest and submitting it
- Improve the Flatpak support in your favorite Linux distribution
Hacking
See CONTRIBUTING.md
Related Projects
Here are some notable projects in the Flatpak ecosystem:
- Flatseal: An app for managing permissions of Flatpak apps without using the CLI
- Flat-manager: A tool for managing Flatpak repositories
Languages
C
91.3%
Shell
5.8%
Meson
1.1%
Python
0.9%
Yacc
0.9%
