Checklist
Flatpak version
1.19.1
What Linux distribution are you using?
Fedora Linux
Linux distribution version
44
What architecture are you using?
x86_64
How to reproduce
With org.freedesktop.Platform//25.08 installed:
flatpak build-init readonly-test org.example.Readonly \
org.freedesktop.Platform org.freedesktop.Platform 25.08
flatpak build readonly-test sh -c '
echo original > /var/lib/marker
echo original > /var/tmp/marker
'
flatpak build --readonly readonly-test sh -c '
echo changed > /var/lib/marker
echo changed > /var/tmp/marker
'
cat readonly-test/var/lib/marker readonly-test/var/tmp/marker
Both files contain changed.
Is that intentional as builds would break otherwise?
Expected Behavior
|
<varlistentry> |
|
<term><option>--readonly</option></term> |
|
|
|
<listitem><para> |
|
Mount the normally writable destination directories read-only. This can |
|
be useful if you want to run something in the sandbox but guarantee that |
|
it doesn't affect the build results. For example tests. |
|
</para></listitem> |
says
--readonly makes normally writable destination directories read-only so the command cannot affect build results.
Actual Behavior
Both writes succeed and change files in the build directory.
The
|
/* Persist some stuff in /var. We can't persist everything because that breaks /var things |
|
* from the host to work. For example the /home -> /var/home on atomic. |
|
* The interesting things to contain during the build is /var/tmp (for tempfiles shared during builds) |
|
* and things like /var/lib/rpm, if the installation uses packages. |
|
*/ |
|
flatpak_bwrap_add_args (bwrap, |
|
"--bind", flatpak_file_get_path_cached (var_lib), "/var/lib", |
|
NULL); |
|
flatpak_bwrap_add_args (bwrap, |
|
"--bind", flatpak_file_get_path_cached (var_tmp), "/var/tmp", |
|
NULL); |
uses writable binds for
/var/lib and
/var/tmp without checking
opt_readonly.
Additional Information
Is keeping these directories writable intentional?
Either --readonly should protect these too (as above in the code), or the documentation should explain which build directories remain writable.
Checklist
Flatpak version
1.19.1
What Linux distribution are you using?
Fedora Linux
Linux distribution version
44
What architecture are you using?
x86_64
How to reproduce
With
org.freedesktop.Platform//25.08installed:Both files contain
changed.Is that intentional as builds would break otherwise?
Expected Behavior
flatpak/doc/flatpak-build.xml
Lines 387 to 394 in 491294f
--readonlymakes normally writable destination directories read-only so the command cannot affect build results.Actual Behavior
Both writes succeed and change files in the build directory.
The
flatpak/app/flatpak-builtins-build.c
Lines 567 to 577 in 491294f
/var/liband/var/tmpwithout checkingopt_readonly.Additional Information
Is keeping these directories writable intentional?
Either
--readonlyshould protect these too (as above in the code), or the documentation should explain which build directories remain writable.