Sebastian Wick eaffd3ce36 system-dir: Prevent removing of deployed refs via the system-helper
We have two use cases for removing refs: uninstalling, and pruning of
undeployed refs. Pruning undeployed refs is something we want anyone to
be able to do, because they can also pull updates and then not deploy
them. Uninstalling arbitrary refs on the other hand is problematic, and
its possible to remove the AppStream ref, and a deployed ref.

So we split removing a ref into a function which removes any ref, and
use it internally to implement e.g. uninstalling, and a function to
remove refs which are safe to remove. Only the latter one will escalate
through the system helper, making it harder for unprivileged users to
get into a state which can be exploited.

See the previous commit for such a state.

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
2026-08-11 01:22:28 +02:00
2026-01-21 17:58:19 +00:00
2026-06-08 14:35:23 +02:00
2022-10-24 16:12:14 +01:00
2026-08-05 15:04:26 +00:00
2022-10-24 16:12:14 +01:00
2026-01-21 17:58:19 +00:00
2018-02-05 15:21:40 +00:00
2015-03-31 15:36:29 +01:00
2022-09-26 14:35:40 +01:00
2026-06-08 14:51:50 +02:00
2026-06-08 14:35:23 +02:00

Flatpak icon

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.

See https://flatpak.org/ for more information.

Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.

Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.

Read documentation for Flatpak here.

Contributing

Flatpak welcomes contributions from anyone! Here are some ways you can help:

Hacking

See CONTRIBUTING.md

Related Projects

Here are some notable projects in the Flatpak ecosystem:

  • Flatseal: An app for managing permissions of Flatpak apps without using the CLI
  • Flat-manager: A tool for managing Flatpak repositories
S
Description
No description provided
Readme LGPL-2.1
119 MiB
0 Stars 1 Watchers 0 Forks
Languages
C 91.3%
Shell 5.8%
Meson 1.1%
Python 0.9%
Yacc 0.9%