Skip to content

remove --delete-data does not work with separate admin user #6080

Description

@boredsquirrel

Hey there!

the default polkit rule only allows wheel users to install and uninstall flatpaks.

when using a separate admin user only for authenticating (via pkexec or the better run0), this means flatpak remove will be executed from that user

this breaks the mechanism to delete user data in ~/.var/app of the nonwheel user.

Fixing the --delete-data function to search in all users would be nice. alternatively, it could somehow be ran separately (without the remove) from the user?

my tool is a workaround for this issue

Activity

  1. changed the title [-]remove --delete-data does not work with run0[/-] [+]remove --delete-data does not work with separate admin user[/+] on Jan 15, 2025
  2. chrisawi commented on Jan 15, 2025

    @chrisawi
    Collaborator

    You can run flatpak uninstall --delete-data, and it will prompt to remove each 'orphaned' data directory.

    flatpak is intended to be run inside the user session, not via sudo or any sudo alternatives (with a few exceptions). In theory, whatever policy you want should be configurable in polkit.

  3. boredsquirrel commented on Jan 19, 2025

    @boredsquirrel
    Author

    Hi @chrisawi that comment was not useful, it is exactly what I describe.

    The goal: have a system where all executable code lies in privileged directories. Flatpaks default polkit rule is fine, as it allows any user to update apps, but installs, uninstalls and remote-changes need privileges.

    Using a wheel/sudo user daily is not good practice. It is trivial to catch a sudo/polkit password and escalate to root level.

    To have a baseline of security, users (or sysadmins) should setup a system once, and then only need to escalate privileges when changing it.

    No user (or user process) should be allowed to decide what executable code they want to run, as this is how you easily get malware.

    So controlling non-executable data is important. I will open a broader issue on this topic.

  4. chrisawi commented on Jan 19, 2025

    @chrisawi
    Collaborator

    As I mentioned in your other issue, there's no need to run flatpak as another user for this scenario:

    $ flatpak install org.example.App
    [...]
    [Admin password prompt]
    [...]
    $ flatpak uninstall --delete-data org.example.App
    [...]
    [Admin password prompt]
    [...]
    Uninstall complete.
    Delete data for org.example.App? [y/n]:
    

    Closing as we don't need two issues on the same topic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions