Skip to content

1.18 backports - #6841

Merged
smcv merged 33 commits into
flatpak:flatpak-1.18.xfrom
smcv:1.18-backports
Sep 21, 2026
Merged

smcv merged 33 commits into
flatpak:flatpak-1.18.xfrom
smcv:1.18-backports

Conversation

@smcv

@smcv smcv commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

The merge commit is the git subtree merge equivalent of #6834.

swick and others added 30 commits September 2, 2026 23:14
The chase_manual shortcut for the NO_AUTOMOUNT-only case stripped the
NO_AUTOMOUNT flag when forwarding to chase_open_tree, causing automounts
to be triggered despite the caller explicitly requesting otherwise.
At this point in the code we reached the ENOTDIR fallback, meaning
the automount is not a directory, but the comment said the opposite.
chase: Fix incorrect comment in chase_open_tree automount fallback

See merge request GNOME/libglnx!81
Needed to add job for newer distro versions
ci: Add build job for Fedora latest, rawhide, debian stable and unstable

See merge request GNOME/libglnx!74
```
In file included from ../subprojects/libglnx/libglnx.h:41,
                 from ../use-libglnx.c:6:
../subprojects/libglnx/glnx-fdio.h:425:41: warning:
'struct file_handle' declared inside parameter list will not be
visible outside of this definition or declaration
```

Signed-off-by: Simon McVittie <[email protected]>
Older compilers default to issuing a warning on missing field
initializers, even though an incomplete initializer has well-defined
behaviour (it initializes all fields to NULL or zero) and we rely on this:

```
../glnx-console.c: In function 'fd_columns':
../glnx-console.c:71:10: warning: missing initializer for field 'ws_row'
of 'struct winsize' [-Wmissing-field-initializers]
   struct winsize ws = {};
```

Signed-off-by: Simon McVittie <[email protected]>
Debian testing is a rolling release a few days older than unstable,
so it's insulated from the worst regressions and other transient bugs,
and often a better choice for upstream CI.

Signed-off-by: Simon McVittie <[email protected]>
Older versions of Meson didn't have `meson dist`.

Signed-off-by: Simon McVittie <[email protected]>
Debian 10 "only" became EOL in 2024 and still has third-party ELTS
support, so it's probably a better example of an older distro than
Fedora 30.

Signed-off-by: Simon McVittie <[email protected]>
This is the oldest environment where libglnx is known to be compiled
and used in production. Although it's generally 2012-era, it does have
a backport of a significantly newer GLib (from 2019), a correspondingly
newer Meson, and a non-default python3.5 interpreter to run Meson.

Signed-off-by: Simon McVittie <[email protected]>
These are a convenient way to get very old build environments.
Flatpak is a major user of libglnx, and theoretically supports being
compiled on GLib 2.46 (although this might not actually work any more;
let's find out).

Signed-off-by: Simon McVittie <[email protected]>
Its role as an obsolete/retrocomputing distribution can be taken by
Debian ELTS, Ubuntu oldLTS or the Steam Runtime.

Signed-off-by: Simon McVittie <[email protected]>
chase: Pass NO_AUTOMOUNT to chase_open_tree in shortcut path

See merge request GNOME/libglnx!80
Add more CI environments

See merge request GNOME/libglnx!85
Fixes: 1345882 "glnx_file_copy_at: Add GLNX_FILE_COPY_NOCHOWN"
Resolves: https://gitlab.gnome.org/GNOME/libglnx/-/work_items/8
Resolves: flatpak/flatpak-builder#770
Signed-off-by: Simon McVittie <[email protected]>
We can't create a symlink that we don't own, but if we are not root
then /dev/stderr will often be an example of such a symlink.

Reproduces: https://gitlab.gnome.org/GNOME/libglnx/-/work_items/8
Signed-off-by: Simon McVittie <[email protected]>
fdio: Don't change ownership of symlinks if not requested

Closes flatpak#8

See merge request GNOME/libglnx!83
We can't use fgetxattr() to get the extended attributes of a symlink via
the magic symlink in /proc/self/fd, because opening with O_NOFOLLOW
would give us the extended attributes of the magic symlink
/proc/self/fd/N, and opening without O_NOFOLLOW would dereference the
symlink.

This reverts commit 036ad70.

Helps: flatpak#6818
We can't use fsetxattr() to get the extended attributes of a symlink via
the magic symlink in /proc/self/fd, because opening with O_NOFOLLOW
would try to set the extended attributes on the magic symlink
/proc/self/fd/N, and opening without O_NOFOLLOW would dereference the
symlink.

This reverts commit 128578b.

Helps: flatpak#6818
Signed-off-by: Simon McVittie <[email protected]>
We can't use fgetxattr() to get the extended attributes of a symlink via
the magic symlink in /proc/self/fd, because opening with O_NOFOLLOW
would give us the extended attributes of the magic symlink
/proc/self/fd/N, and opening without O_NOFOLLOW would dereference the
symlink.

This reverts commit fc9387a.

Helps: flatpak#6818
Signed-off-by: Simon McVittie <[email protected]>
There is currently no kernel interface to set extended attributes on
a symbolic link by its O_PATH fd: fsetxattr() on the O_PATH fd itself
fails because we do not have write access, if we reopen the fd via
`/proc/self/fd/N` with O_NOFOLLOW and then use fsetxattr() then that
will attempt to set the xattrs on the magic symlink in /proc instead of
on the symlink we originally created, and if we reopen the fd via
`/proc/self/fd/N` without O_NOFOLLOW then that will attempt to set the
xattrs on the symlink's target. The best we can do is to call
lsetxattr() relative to the destination directory.

This partially reverts commit 6bb0320 "glnx_file_copy_at: Use O_PATH fd
for xattr and ownership operations".

Helps: flatpak#6818
Co-authored-by:Sebastian Wick <[email protected]>
Signed-off-by: Simon McVittie <[email protected]>
Unfortunately we can't generally test this as an ordinary user.
Ordinary users are only allowed to set extended attributes in the
`user.` namespace, but Linux doesn't currently support setting xattrs in
that namespace on a symlink.

If we are running as root (as we do in the CI), then we can set extended
attributes in the `trusted.`, `system.` or `security.` namespaces,
which Linux *does* support setting on symlinks. Of these, `trusted.`
has no particular semantics at the kernel level (it's available to
user-space) so that seems like the best one to use for testing.

Signed-off-by: Simon McVittie <[email protected]>
fdio: Don't try to use fd-relative operations to set symlink xattrs

See merge request GNOME/libglnx!84
It contains a crucial security fix for mount destination path
resolution.

(cherry picked from commit 540a487)
flatpak_context_to_args() built the D-Bus name options from
flatpak_policy_to_string(). That function gives the values used in the
[Session Bus Policy] and [System Bus Policy] metadata groups. Two of
them, "none" and "see", are not command-line options. A context that
contained such a policy gave --none-name= and --system-none-name=.

flatpak-run(1) writes these arguments to the [Instance] extra-args of
/.flatpak-info. flatpak-portal gives them back to flatpak(1) when a
sandboxed app calls flatpak-spawn(1). flatpak(1) then rejected the whole
command line with "Unknown option --none-name=...", so --no-talk-name
and --system-no-talk-name broke flatpak-spawn(1).

Map each policy to the option that sets it: --no-talk-name for
FLATPAK_POLICY_NONE, --talk-name for FLATPAK_POLICY_TALK, and --own-name
for FLATPAK_POLICY_OWN. FLATPAK_POLICY_SEE has no command-line option,
so emit nothing for it. It cannot occur here: the only caller serializes
a context that comes from the command line.

(cherry picked from commit 7c764d2)
….18.x

  * chase: Pass NO_AUTOMOUNT to chase_open_tree in shortcut path
  * chase: Fix incorrect comment
  * build: Suppress `-Wmissing-field-initializers`
  * fdio: Don't change ownership of symlinks if not requested
    (Resolves: flatpak/flatpak-builder#770)
  * fdio: Don't try to use fd-relative operations to set symlink xattrs
    (Resolves: flatpak#6818)

Signed-off-by: Simon McVittie <[email protected]>
@swick

swick commented Sep 21, 2026

Copy link
Copy Markdown
Collaborator

should probably add #6842 as well

@smcv

smcv commented Sep 21, 2026

Copy link
Copy Markdown
Collaborator Author

should probably add #6842 as well

Yeah, and a NEWS update based on #6843.

Because this updates the subtree, I'll push directly after approval instead of using the queue.

razzeee and others added 2 commits September 21, 2026 17:04
BundleData retains explicit GPG key data with g_bytes_ref(), but its
cleanup treats the data as a GObject. This crashes transaction cleanup
when a bundle is installed with explicit key bytes.

Use g_clear_pointer() with g_bytes_unref() to release the retained data.

(cherry picked from commit 95b70b7)
Signed-off-by: Simon McVittie <[email protected]>
@smcv

smcv commented Sep 21, 2026

Copy link
Copy Markdown
Collaborator Author

Updated to include #6842 as well.

@smcv
smcv marked this pull request as ready for review September 21, 2026 16:30
@smcv
smcv requested a review from swick September 21, 2026 16:31

@swick swick left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also LGTM

@smcv
smcv merged commit 4c23fb6 into flatpak:flatpak-1.18.x Sep 21, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants