Skip to content

dir: Ignore system bus failures in parental controls check - #6663

Merged
swick merged 1 commit into
flatpak:mainfrom
alatiera:alatiera/install-error
May 27, 2026
Merged

swick merged 1 commit into
flatpak:mainfrom
alatiera:alatiera/install-error

Conversation

@alatiera

Copy link
Copy Markdown
Contributor

Being unable to access the system-bus is nto a security boundry since,
in that case it's trivial to start your own session and set
DBUS_SYSTEM_BUS_ADDRESS. This is the same fix as 3afdfd2 but for handling
installation instead. See said commit for more details.

Adapted from #5609
Fixes #5076

Co-authored-by: Dan Nicholson [email protected]

Being unable to access the system-bus is nto a security boundry since,
in that case it's trivial to start your own session and set
DBUS_SYSTEM_BUS_ADDRESS. This is the same fix as 3afdfd2 but for handling
installation instead. See said commit for more details.

Adapted from flatpak#5609
Fixes flatpak#5076

Co-authored-by: Dan Nicholson <[email protected]>
@alatiera

Copy link
Copy Markdown
Contributor Author

Draft cause I haven't finished testing this yet.

Comment thread common/flatpak-dir.c
"bus connection failed: %s",
ref,
local_error ? local_error->message : "unknown reason");
return TRUE;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I would have preferred a stricter version where we return true only if it is unreachable or not found in standard location. A blanket return true is a bit dubious to me.

I'm not sure why this was not done in the original commit.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The other one has this exact code, so I'm going ahead and merge this. If you think this should be changed, please open a new PR and change it at both places.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I talked about doing a stricter test in #5076 (comment), but obviously I didn't do that. I think I just wasn't sure what all the expected errors would be and punted. I agree it would be good, though.

@alatiera

alatiera commented May 17, 2026 •

Copy link
Copy Markdown
Contributor Author

Here is the testcase, this patch works fine for user installations now.

Slightly modified from @bbhtt as --system repos explode and I don't think we should bother with them at all in unpriv contianers in CI anyway.

FROM fedora:44

RUN dnf install -y flatpak sudo ostree git && dnf builddep -y flatpak && dnf clean all

RUN mkdir -p /var/lib/flatpak/repo
RUN mkdir -p /var/local/lib/flatpak/repo
RUN ostree init --repo=/var/lib/flatpak/repo --mode=bare-user-only
RUN ostree init --repo=/var/local/lib/flatpak/repo --mode=bare-user-only

RUN useradd -m -s /bin/bash -u 1000 -G wheel appuser && \
    echo '%wheel ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/wheel && \
    chmod 0440 /etc/sudoers.d/wheel

# Or mount it locally with --userns=keep-id --volume=(pwd):/home/appuser/flatpak --workdir=/home/appuser/flatpak
RUN git clone --depth=1 --branch alatiera/install-error https://github.com/alatiera/flatpak.git /tmp/flatpak

RUN cd /tmp/flatpak && \
    meson setup --prefix=/usr -Dgtkdoc=disabled -Dtests=false -Dmalcontent=enabled -Dsystem_dbus_proxy=xdg-dbus-proxy _builddir_fedora && \
    meson compile -C _builddir_fedora && \
    meson install -C _builddir_fedora

USER appuser
ENV HOME=/home/appuser
WORKDIR /home/appuser

ENTRYPOINT ["/bin/bash"]

RUN flatpak remote-add --user --if-not-exists flathub \
    https://flathub.org/repo/flathub.flatpakrepo

RUN flatpak install -y --user --no-deps --no-related -y org.gnome.Calculator
# If run as non-root it fails cause it will try to check for the
# system helper in the bus in flatpak-dir.c:2808 and fail
# error: Unable to connect to system bus
#
# https://github.com/flatpak/flatpak/blob/588eef8e65c94af037c4855577535769994a2e05/common/flatpak-dir.c#L2808-L2825
#
# RUN flatpak -vv remote-add --system --if-not-exists flathub \
#     https://flathub.org/repo/flathub.flatpakrepo
# RUN flatpak install -y --system --no-deps --no-related -y org.gnome.Calculator

@alatiera
alatiera marked this pull request as ready for review May 17, 2026 10:08
@swick
swick added this pull request to the merge queue May 27, 2026
Merged via the queue into flatpak:main with commit 9a813ff May 27, 2026
11 checks passed
@alatiera
alatiera deleted the alatiera/install-error branch June 17, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Flatpak app inside Docker fails with: Could not connect: No such file or directory

4 participants