Repository navigation
dir: Ignore system bus failures in parental controls check - #6663
Conversation
Being unable to access the system-bus is nto a security boundry since, in that case it's trivial to start your own session and set DBUS_SYSTEM_BUS_ADDRESS. This is the same fix as 3afdfd2 but for handling installation instead. See said commit for more details. Adapted from flatpak#5609 Fixes flatpak#5076 Co-authored-by: Dan Nicholson <[email protected]>
|
Draft cause I haven't finished testing this yet. |
| "bus connection failed: %s", | ||
| ref, | ||
| local_error ? local_error->message : "unknown reason"); | ||
| return TRUE; |
There was a problem hiding this comment.
I think I would have preferred a stricter version where we return true only if it is unreachable or not found in standard location. A blanket return true is a bit dubious to me.
I'm not sure why this was not done in the original commit.
There was a problem hiding this comment.
The other one has this exact code, so I'm going ahead and merge this. If you think this should be changed, please open a new PR and change it at both places.
There was a problem hiding this comment.
I talked about doing a stricter test in #5076 (comment), but obviously I didn't do that. I think I just wasn't sure what all the expected errors would be and punted. I agree it would be good, though.
|
Here is the testcase, this patch works fine for user installations now. Slightly modified from @bbhtt as --system repos explode and I don't think we should bother with them at all in unpriv contianers in CI anyway. FROM fedora:44
RUN dnf install -y flatpak sudo ostree git && dnf builddep -y flatpak && dnf clean all
RUN mkdir -p /var/lib/flatpak/repo
RUN mkdir -p /var/local/lib/flatpak/repo
RUN ostree init --repo=/var/lib/flatpak/repo --mode=bare-user-only
RUN ostree init --repo=/var/local/lib/flatpak/repo --mode=bare-user-only
RUN useradd -m -s /bin/bash -u 1000 -G wheel appuser && \
echo '%wheel ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/wheel && \
chmod 0440 /etc/sudoers.d/wheel
# Or mount it locally with --userns=keep-id --volume=(pwd):/home/appuser/flatpak --workdir=/home/appuser/flatpak
RUN git clone --depth=1 --branch alatiera/install-error https://github.com/alatiera/flatpak.git /tmp/flatpak
RUN cd /tmp/flatpak && \
meson setup --prefix=/usr -Dgtkdoc=disabled -Dtests=false -Dmalcontent=enabled -Dsystem_dbus_proxy=xdg-dbus-proxy _builddir_fedora && \
meson compile -C _builddir_fedora && \
meson install -C _builddir_fedora
USER appuser
ENV HOME=/home/appuser
WORKDIR /home/appuser
ENTRYPOINT ["/bin/bash"]
RUN flatpak remote-add --user --if-not-exists flathub \
https://flathub.org/repo/flathub.flatpakrepo
RUN flatpak install -y --user --no-deps --no-related -y org.gnome.Calculator
# If run as non-root it fails cause it will try to check for the
# system helper in the bus in flatpak-dir.c:2808 and fail
# error: Unable to connect to system bus
#
# https://github.com/flatpak/flatpak/blob/588eef8e65c94af037c4855577535769994a2e05/common/flatpak-dir.c#L2808-L2825
#
# RUN flatpak -vv remote-add --system --if-not-exists flathub \
# https://flathub.org/repo/flathub.flatpakrepo
# RUN flatpak install -y --system --no-deps --no-related -y org.gnome.Calculator |
Being unable to access the system-bus is nto a security boundry since,
in that case it's trivial to start your own session and set
DBUS_SYSTEM_BUS_ADDRESS. This is the same fix as 3afdfd2 but for handling
installation instead. See said commit for more details.
Adapted from #5609
Fixes #5076
Co-authored-by: Dan Nicholson [email protected]