mirror of
https://github.com/flatpak/flatpak.git
synced 2026-10-06 12:59:38 -04:00
660d3dfcfd18cc5162df116614032d34fe5e84b7
handle_remove_local_ref validates the remote name but passes the ref string directly to flatpak_dir_remove_ref without validation. Since the polkit action for this method is modify-repo (allow_active=yes), any active session user can delete arbitrary ostree refs in the system repo without authentication. All legitimate callers of RemoveLocalRef pass standard flatpak refs (app/runtime). Non-standard refs like appstream/, appstream2/, and ostree-metadata are managed through their own dedicated D-Bus methods (DeployAppstream, UpdateRemote, ConfigureRemote) and never go through RemoveLocalRef. Validate the ref with flatpak_decomposed_new_from_ref() to restrict removal to valid flatpak refs.
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
See https://flatpak.org/ for more information.
Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.
Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.
Read documentation for Flatpak here.
Contributing
Flatpak welcomes contributions from anyone! Here are some ways you can help:
- Fix one of the issues and submit a PR
- Update flatpak's translations and submit a PR
- Improve flatpak's documentation, hosted at http://docs.flatpak.org and developed over in flatpak-docs
- Find a bug and submit a detailed report including your OS, flatpak version, and the steps to reproduce
- Add your favorite application to Flathub by writing a flatpak-builder manifest and submitting it
- Improve the Flatpak support in your favorite Linux distribution
Hacking
See CONTRIBUTING.md
Related Projects
Here are some notable projects in the Flatpak ecosystem:
- Flatseal: An app for managing permissions of Flatpak apps without using the CLI
- Flat-manager: A tool for managing Flatpak repositories
Languages
C
91.2%
Shell
6%
Meson
1.1%
Python
0.9%
Yacc
0.8%
