Skip to content

run: Ignore system bus failures in parental controls check - #5609

Merged
smcv merged 1 commit into
flatpak:mainfrom
dbnicholson:malcontent-system-bus
Dec 8, 2023
Merged

smcv merged 1 commit into
flatpak:mainfrom
dbnicholson:malcontent-system-bus

Conversation

@dbnicholson

Copy link
Copy Markdown
Contributor

Currently if the parental controls check can't connect to the system bus, apps are not allowed to run. However, apps are also allowed to run if the malcontent (or accounts-service) D-Bus services aren't available. Since it's trivial to meet that requirement by starting a temporary dbus-daemon and setting DBUS_SYSTEM_BUS_ADDRESS to use it, not being able to access the system bus at all is no less secure.

This primarily affects flatpak running in a container where D-Bus is generally not available.

Fixes: #5076

dbnicholson added a commit to endlessm/flatpak that referenced this pull request Nov 29, 2023
Currently if the parental controls check can't connect to the system
bus, apps are not allowed to run. However, apps are also allowed to run
if the malcontent (or accounts-service) D-Bus services aren't available.
Since it's trivial to meet that requirement by starting a temporary
dbus-daemon and setting `DBUS_SYSTEM_BUS_ADDRESS` to use it, not being
able to access the system bus at all is no less secure.

This primarily affects flatpak running in a container where D-Bus is
generally not available.

Fixes: #5076
(cherry picked from commit 3f0a4c717db53e198838b9e1e8895dda0b073f5d)
Upstream: flatpak/flatpak#5609

https://phabricator.endlessm.com/T35067
dbnicholson added a commit to endlessm/flatpak that referenced this pull request Nov 30, 2023
Currently if the parental controls check can't connect to the system
bus, apps are not allowed to run. However, apps are also allowed to run
if the malcontent (or accounts-service) D-Bus services aren't available.
Since it's trivial to meet that requirement by starting a temporary
dbus-daemon and setting `DBUS_SYSTEM_BUS_ADDRESS` to use it, not being
able to access the system bus at all is no less secure.

This primarily affects flatpak running in a container where D-Bus is
generally not available.

Fixes: #5076
(cherry picked from commit 3f0a4c717db53e198838b9e1e8895dda0b073f5d)
Upstream: flatpak/flatpak#5609

https://phabricator.endlessm.com/T35067
@smcv
smcv requested a review from pwithnall November 30, 2023 13:24
@smcv

smcv commented Nov 30, 2023

Copy link
Copy Markdown
Collaborator

Looks reasonable to me, but I'd like an ack from @pwithnall as the author of this feature.

@pwithnall

Copy link
Copy Markdown
Collaborator

I’m happy if you’re happy.

Too much human time and effort has been wasted (across so many projects) on the fact that containers, for some reason, don’t have D-Bus 😞

Currently if the parental controls check can't connect to the system
bus, apps are not allowed to run. However, apps are also allowed to run
if the malcontent (or accounts-service) D-Bus services aren't available.
Since it's trivial to meet that requirement by starting a temporary
dbus-daemon and setting `DBUS_SYSTEM_BUS_ADDRESS` to use it, not being
able to access the system bus at all is no less secure.

This primarily affects flatpak running in a container where D-Bus is
generally not available.

Fixes: flatpak#5076
@smcv
smcv force-pushed the malcontent-system-bus branch from 3f0a4c7 to c1c4e1c Compare December 5, 2023 13:55
@smcv
smcv merged commit 3afdfd2 into flatpak:main Dec 8, 2023
bbhtt pushed a commit to flathub-infra/flatpak that referenced this pull request May 27, 2026
Being unable to access the system-bus is nto a security boundry since,
in that case it's trivial to start your own session and set
DBUS_SYSTEM_BUS_ADDRESS. This is the same fix as 3afdfd2 but for handling
installation instead. See said commit for more details.

Adapted from flatpak#5609
Fixes flatpak#5076

Co-authored-by: Dan Nicholson <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Flatpak app inside Docker fails with: Could not connect: No such file or directory

3 participants