Repository navigation
system-helper: Authenticate via polkit for system wide downgrades - #6669
Conversation
| if ((flags & FLATPAK_HELPER_DEPLOY_FLAGS_ALLOW_DOWNGRADE) != 0) | ||
| action = "org.freedesktop.Flatpak.runtime-downgrade"; | ||
| else |
There was a problem hiding this comment.
So, I find this a bit problematic: the flag is something an untrusted caller can just specify to force the action to become org.freedesktop.Flatpak.app-downgrade, even if the actual operation isn't a downgrade!
Not sure if we should care. I think if we properly document that the org.freedesktop.Flatpak.app-downgrade action includes the org.freedesktop.Flatpak.app-update action, we should be fine.
|
But yeah, besides documenting the action properly, this looks good. |
|
I have added the documentation to |
|
The annotation is a great improvement but the text itself should also shorty explain this. |
|
Ok, I added the security notes. Or did you mean that the user facting message tags needed a short explanation instead? |
|
Thanks, the note is what I had in mind. Do you mind squashing the latter two commits into the first one (the history here isn't meaningful)? The commit message also needs to be formatted properly (mostly the line limit of 80 chars). |
Downgrading an app or runtime previously failed outright for non root users calling through the system helper, with an error stating that updating to a specific commit requires root permissions. Instead, allow downgrades through the system helper by introducing a new flag that is set when the caller requests a downgrade. New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade" polkit actions are added that require auth_admin_keep for active users.
|
Sorry, I missed your comment. I just noticed it after receiving another email. It looks like all the commits have already been squashed. Is there still anything I should do? |
|
No, all good, I just did the trivial changes myself. Thanks for the contribution. |
Downgrading an app or runtime previously failed outright for non root users calling through the system helper, with an error stating that updating to a specific commit requires root permissions.
Instead, allow downgrades through the system helper by introducing a new flag that is set when the caller requests a downgrade. New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade" polkit actions are added that require auth_admin_keep for active users.
Closes #3831