Skip to content

[Bug]: flatpak build --readonly leaves persistent /var directories writable #6857

Description

@razzeee

Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for a bug that matches the one I want to file, without success.
  • If this is an issue with a particular app, I have tried filing it in the appropriate issue tracker for the app (e.g. under https://github.com/flathub/) and determined that it is an issue with Flatpak itself.
  • This issue is not a report of a security vulnerability (see here if you need to report a security issue).

Flatpak version

1.19.1

What Linux distribution are you using?

Fedora Linux

Linux distribution version

44

What architecture are you using?

x86_64

How to reproduce

With org.freedesktop.Platform//25.08 installed:

flatpak build-init readonly-test org.example.Readonly \
  org.freedesktop.Platform org.freedesktop.Platform 25.08

flatpak build readonly-test sh -c '
  echo original > /var/lib/marker
  echo original > /var/tmp/marker
'

flatpak build --readonly readonly-test sh -c '
  echo changed > /var/lib/marker
  echo changed > /var/tmp/marker
'

cat readonly-test/var/lib/marker readonly-test/var/tmp/marker

Both files contain changed.

Is that intentional as builds would break otherwise?

Expected Behavior

<varlistentry>
<term><option>--readonly</option></term>
<listitem><para>
Mount the normally writable destination directories read-only. This can
be useful if you want to run something in the sandbox but guarantee that
it doesn't affect the build results. For example tests.
</para></listitem>
says --readonly makes normally writable destination directories read-only so the command cannot affect build results.

Actual Behavior

Both writes succeed and change files in the build directory.

The

/* Persist some stuff in /var. We can't persist everything because that breaks /var things
* from the host to work. For example the /home -> /var/home on atomic.
* The interesting things to contain during the build is /var/tmp (for tempfiles shared during builds)
* and things like /var/lib/rpm, if the installation uses packages.
*/
flatpak_bwrap_add_args (bwrap,
"--bind", flatpak_file_get_path_cached (var_lib), "/var/lib",
NULL);
flatpak_bwrap_add_args (bwrap,
"--bind", flatpak_file_get_path_cached (var_tmp), "/var/tmp",
NULL);
uses writable binds for /var/lib and /var/tmp without checking opt_readonly.

Additional Information

Is keeping these directories writable intentional?

Either --readonly should protect these too (as above in the code), or the documentation should explain which build directories remain writable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions