mirror of
https://github.com/flatpak/flatpak.git
synced 2026-10-06 12:59:38 -04:00
c68be6274eedb4eed9d79dbf02856482de6b7a83
Use glnx_chaseat to ensure that the attacker-controlled symlink name ends up inside the basefd directory. Note that the symlink *target* is also attacker-controlled, but it's OK for them to be able to set any target of their choice: that can't immediately cause traversal outside the base directory. [smcv: Separated from a larger commit for better reviewability] Co-authored-by: Simon McVittie <smcv@collabora.com> Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
See https://flatpak.org/ for more information.
Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.
Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.
Read documentation for Flatpak here.
Contributing
Flatpak welcomes contributions from anyone! Here are some ways you can help:
- Fix one of the issues and submit a PR
- Update flatpak's translations and submit a PR
- Improve flatpak's documentation, hosted at http://docs.flatpak.org and developed over in flatpak-docs
- Find a bug and submit a detailed report including your OS, flatpak version, and the steps to reproduce
- Add your favorite application to Flathub by writing a flatpak-builder manifest and submitting it
- Improve the Flatpak support in your favorite Linux distribution
Hacking
See CONTRIBUTING.md
Related Projects
Here are some notable projects in the Flatpak ecosystem:
- Flatseal: An app for managing permissions of Flatpak apps without using the CLI
- Flat-manager: A tool for managing Flatpak repositories
Languages
C
91.2%
Shell
6%
Meson
1.1%
Python
0.9%
Yacc
0.8%
