[Bug]: remote-ls --updates reports up-to-date OCI refs because it ignores deployed Alt-id
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 72/100
Direzione di ricerca
Inizia dal filtro opt_only_updates in app/flatpak-builtins-remote-ls.c, che attualmente confronta il checksum remoto solo con il commit distribuito. Verifica come flatpak_dir_needs_update_for_commit_and_subpaths() accetti anche il Alt-id, quindi fai in modo che l'elenco escluda un ref quando il checksum corrisponde a una delle due identità. Esegui tests/test-oci-registry.sh: il lavoro è completato quando la nuova asserzione no-updates-after-install passa in tutte le varianti OCI e i controlli di aggiornamento esistenti continuano a passare.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Problem
flatpak remote-ls --updates reports already installed applications and runtimes from an OCI remote as pending updates, while flatpak update correctly reports nothing to update.
This is a focused report of the OCI mismatch also described in #6714, which was closed after discussing the unrelated flatpak list --columns=latest behavior. It also resembles #3748.
Environment
- Fedora Linux 44, x86_64
- Flatpak 1.18.4 (1.18.4-1.fc44)
- Fedora remote:
oci+https://registry.fedoraproject.org - Also reproduced in upstream main at
f2df7b090b69487f812f4ea389edffca0f5a4610using the existing fake OCI registry tests.
Reproduction
With an already updated application installed from the Fedora OCI remote:
flatpak remote-ls --system --updates --columns=app fedora
flatpak update --system org.mozilla.firefox
flatpak info --system org.mozilla.firefox
flatpak remote-info --system fedora org.mozilla.firefox
The first command lists Firefox and five installed Fedora runtimes/extensions on this machine; the update transaction reports nothing to update.
For Firefox 156.0.1:
- Installed OSTree commit:
b306883250448dca17929560c62733e68c612ad4c14dac75e70a0f31cc92e038 - Installed Alt-id:
5346c30ccd813306ff00a515c913335952c4353e32d5ecc344479068a71ab384 - Remote commit:
5346c30ccd813306ff00a515c913335952c4353e32d5ecc344479068a71ab384
Cause and proposed correction
The opt_only_updates filter in app/flatpak-builtins-remote-ls.c compares the remote checksum only against flatpak_deploy_data_get_commit(). OCI remotes return the image digest, which matches the deployed Alt-id instead.
The transaction path already handles both identities in flatpak_dir_needs_update_for_commit_and_subpaths(). The listing should similarly exclude a ref when the checksum equals either its installed commit or Alt-id, preserving the existing origin check.
Regression coverage and validation
A regression test added to tests/test-oci-registry.sh checks:
- No updates immediately after installing an OCI app and runtime.
- Only the app is listed after publishing a genuine new OCI image.
- No updates after applying that update.
Before the fix, the first assertion fails with org.test.Hello and org.test.Platform incorrectly listed. After the fix, all four user/system × HTTP/HTTPS OCI registry variants pass (20 subtests each, 80 total). The locally built fixed CLI also reports zero Fedora updates on the affected installation, versus six with the installed CLI.
Workaround
Use flatpak update to check and apply actual updates rather than treating this OCI remote-ls --updates output as authoritative. The discrepancy can make GNOME Software appear to miss updates even when these particular refs are already current; this report does not establish a GNOME Software defect.
A corresponding patch and regression tests will follow in a PR. I agree to follow the project Code of Conduct.
- Lingua principale
- C
- Stelle
- 5.1k
- Fork
- 526
- Merge medio
- 1g 19h
- PR unite (30g)
- 24
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di flatpak/flatpak
-
enhancement needs triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
bug cli
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
flatpak/flatpak#6132 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement libflatpak
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
flatpak/flatpak#5958 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
cli enhancement low priority
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di flatpak/flatpak
Issue simili
-
IO.get_env on Node truncates names at embedded NULForse già presa @Yi-111-a l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
HigherOrderCO/Bend#1449 · 1 commento ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
FujiNetWIFI/fujinet-firmware#1872 ·
I maintainer di solito rispondono entro 1 giorno
-
bug C/C++ code
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
webarkit/WebARKitLib#84 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
OpenPrinting/cups#1751 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
obsproject/obs-studio#14013 ·
I maintainer di solito rispondono entro 1 giorno