Skip to content

system-helper: Authenticate via polkit for system wide downgrades - #6669

Merged
swick merged 1 commit into
flatpak:mainfrom
AlexanderVanhee:downgrade-polkit
Jul 27, 2026
Merged

swick merged 1 commit into
flatpak:mainfrom
AlexanderVanhee:downgrade-polkit

Conversation

@AlexanderVanhee

Copy link
Copy Markdown
Contributor

Downgrading an app or runtime previously failed outright for non root users calling through the system helper, with an error stating that updating to a specific commit requires root permissions.

Instead, allow downgrades through the system helper by introducing a new flag that is set when the caller requests a downgrade. New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade" polkit actions are added that require auth_admin_keep for active users.

Closes #3831

Comment on lines +1954 to +1956
if ((flags & FLATPAK_HELPER_DEPLOY_FLAGS_ALLOW_DOWNGRADE) != 0)
action = "org.freedesktop.Flatpak.runtime-downgrade";
else

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So, I find this a bit problematic: the flag is something an untrusted caller can just specify to force the action to become org.freedesktop.Flatpak.app-downgrade, even if the actual operation isn't a downgrade!

Not sure if we should care. I think if we properly document that the org.freedesktop.Flatpak.app-downgrade action includes the org.freedesktop.Flatpak.app-update action, we should be fine.

@swick

swick commented May 27, 2026

Copy link
Copy Markdown
Collaborator

But yeah, besides documenting the action properly, this looks good.

@AlexanderVanhee

Copy link
Copy Markdown
Contributor Author

I have added the documentation to app-downgrade and runtime-downgrade actions.

@swick

swick commented Jun 7, 2026

Copy link
Copy Markdown
Collaborator

The annotation is a great improvement but the text itself should also shorty explain this.

@AlexanderVanhee

AlexanderVanhee commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor Author

Ok, I added the security notes. Or did you mean that the user facting message tags needed a short explanation instead?

@swick

swick commented Jun 23, 2026

Copy link
Copy Markdown
Collaborator

Thanks, the note is what I had in mind. Do you mind squashing the latter two commits into the first one (the history here isn't meaningful)? The commit message also needs to be formatted properly (mostly the line limit of 80 chars).

Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.

Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
@swick
swick force-pushed the downgrade-polkit branch from 2ef38e4 to 10aa231 Compare July 27, 2026 13:51
@AlexanderVanhee

Copy link
Copy Markdown
Contributor Author

Sorry, I missed your comment. I just noticed it after receiving another email. It looks like all the commits have already been squashed. Is there still anything I should do?

@swick
swick added this pull request to the merge queue Jul 27, 2026
@swick

swick commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

No, all good, I just did the trivial changes myself. Thanks for the contribution.

Merged via the queue into flatpak:main with commit 7777fea Jul 27, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Downgrading requires root without polkit support

2 participants