Files
flatpak/system-helper
Sebastian Wick 660d3dfcfd system-helper: Validate ref in RemoveLocalRef
handle_remove_local_ref validates the remote name but passes the ref
string directly to flatpak_dir_remove_ref without validation. Since the
polkit action for this method is modify-repo (allow_active=yes), any
active session user can delete arbitrary ostree refs in the system repo
without authentication.

All legitimate callers of RemoveLocalRef pass standard flatpak refs
(app/runtime). Non-standard refs like appstream/, appstream2/, and
ostree-metadata are managed through their own dedicated D-Bus methods
(DeployAppstream, UpdateRemote, ConfigureRemote) and never go through
RemoveLocalRef.

Validate the ref with flatpak_decomposed_new_from_ref() to restrict
removal to valid flatpak refs.
2026-08-04 11:38:22 +00:00
..