Public bug reported:

After completing the Ubuntu Studio live installer (ubuntu-desktop-
bootstrap), the splash screen intended to provide visual feedback during
theme switching fails to display when using the org.ubuntustudio-
dark.desktop theme.

Error message:

kf6.package: Path traversal attempt detected: "/usr/share/plasma/look-
and-feel/org.ubuntustudio.desktop/contents/splash/Splash.qml" is not
inside "/usr/share/plasma/look-and-feel/org.ubuntustudio-dark.desktop/"

Cause:

KDE Frameworks 6 has a security restriction that prevents loading QML
files (even via symlinks) that resolve outside the currently active
look-and-feel theme directory. The installer service was attempting to
show a splash from org.ubuntustudio.desktop while org.ubuntustudio-
live.desktop was still active.

Fix:

Add a dedicated PostInstallSplash.qml and required images directly to the 
org.ubuntustudio-live.desktop theme
Reorder ExecStopPost commands to show the splash before switching themes, while 
the live theme is still active

** Affects: ubuntustudio-default-settings (Ubuntu)
     Importance: High
     Assignee: Erich Eickmeyer (eeickmeyer)
         Status: In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2146592

Title:
  Post-installer splash screen fails due to KF6 path traversal check

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntustudio-default-settings/+bug/2146592/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to