Skip to content

oci-registry: Check signatures from mirrored repo in the system helper - #6682

Merged
swick merged 4 commits into
flatpak:mainfrom
swick:wip/oci-deploy-no-fetch-remote
Jun 11, 2026
Merged

swick merged 4 commits into
flatpak:mainfrom
swick:wip/oci-deploy-no-fetch-remote

Conversation

@swick

@swick swick commented Jun 10, 2026

Copy link
Copy Markdown
Collaborator

In flatpak_pull_from_oci we can be in in the system helper where we pull the mirrored OCI image into the system repo. However, to check for signatures in GPG signed repos, we used an OciImageSource in the repo to fetch the signatures. This caused fetching some data from the registry which we don't want in the deploy method, and also fails if a token is required to access the repo.

This change uses the signatures in the mirrored OCI repo instead of pulling them from the lookaside server. The signatures can come from anywhere because we verify them against the GPG key in the system repo.

@owtaylor owtaylor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As far as I can tell without testing, this should fix the problem. I do find the result a bit hard and confusing to read - some suggestions for improving attached.

Comment thread common/flatpak-oci-registry-private.h Outdated
Comment thread common/flatpak-oci-registry.c Outdated
swick added 2 commits June 11, 2026 17:24
In flatpak_pull_from_oci we can be in in the system helper where we pull
the mirrored OCI image into the system repo. However, to fetch the
signatures in GPG signed repos, we used a remote OciImageSource created
through `flatpak_remote_state_fetch_image_source`. This caused fetching
some data from the registry which we don't want in the deploy method,
and also fails if a token is required to access the repo.

This change fetches the signatures from the mirrored OCI repo instead of
pulling them from the remote OciImageSource. The signatures can come from
anywhere because we verify them against the GPG key in the system repo.

The important bit is the change in `flatpak_pull_from_oci` where we now
pass in the local image_source to fetch the signatures from, and in the
system helper, where we get the right metadata to check the signatures
against (eventually ends up in `flatpak_oci_signatures_verify`).
@swick
swick force-pushed the wip/oci-deploy-no-fetch-remote branch from a41c990 to 7809169 Compare June 11, 2026 15:33
…istry

Add infrastructure for testing OCI installations from auth-protected
registries. The mock server now supports requiring a bearer token on all
/v2/ requests, configurable via a new POST /testing-auth/configure admin
endpoint. The client gains a corresponding 'configure-auth' subcommand.

Assisted-by: Cursor
@swick
swick marked this pull request as ready for review June 11, 2026 15:41
@swick

swick commented Jun 11, 2026

Copy link
Copy Markdown
Collaborator Author

Thanks @owtaylor, improved the code according to your suggestions. This now also includes @1pav's test.

Add a regression test that installs from an auth-protected OCI registry.
The registry requires a bearer token for all /v2/ requests; the client
authenticates via the mock test authenticator and the installation
completes successfully. The test runs for both user and system install
paths.

Assisted-by: Cursor

@owtaylor owtaylor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

@swick
swick force-pushed the wip/oci-deploy-no-fetch-remote branch from 3e3f80d to 35efa19 Compare June 11, 2026 18:19
@swick

swick commented Jun 11, 2026

Copy link
Copy Markdown
Collaborator Author

Pulled in trivial changes from #6683

@swick
swick enabled auto-merge June 11, 2026 18:20
@swick
swick added this pull request to the merge queue Jun 11, 2026
Merged via the queue into flatpak:main with commit b9c3cdd Jun 11, 2026
20 checks passed
@swick
swick deleted the wip/oci-deploy-no-fetch-remote branch June 11, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants