Skip to content

feat: Add Bazaar Search Provider for Launcher - #139

Draft
dumbasaroc wants to merge 6 commits into
noctalia-dev:mainfrom
dumbasaroc:main
Draft

feat: Add Bazaar Search Provider for Launcher#139
dumbasaroc wants to merge 6 commits into
noctalia-dev:mainfrom
dumbasaroc:main

Conversation

@dumbasaroc

@dumbasaroc dumbasaroc commented Jul 29, 2026

Copy link
Copy Markdown

Plugin

  • Id: dumbasaroc/bazaarsearch
  • New plugin
  • Update to an existing plugin (version bumped in plugin.toml)

What it does

Bazaar Search allows users to search for Flatpaks directly though the Noctalia Launcher. It works very similarly to KDE's Discover search in KRunner and Gnome Software search in GNOME's application search bar. Users search via /bzr <search terms> and can select Flatpak entries in the launcher. When clicked, they bring the user to the specified page in the Bazaar application.

External dependencies

  • busctl (part of systemd)
  • Bazaar Flatpak Store (either installed via package manager or via Flatpak)

Testing

All of this was tested on my development machine, currently running
CachyOS Rolling, Noctalia v5, and niri 26.04.

  • Changed max_entries to 0 (shows nothing), 5 (shows five or less entries), 10 (shows 10 or less entries), and 50 (shows 50 or less entries).

  • Attempted with both Flatpak and binary versions of bazaar

    • Provided the Bazaar background service is online, both work.
  • Opened plugin launcher provider without having the service online

    • If binary was installed (in my case, via pacman), plugin worked fine - it automatically opened the application via invoking the DBus interface.
    • If Flatpak was installed, plugin could not reopen the DBus interface due to Flatpak's sandboxing.
  • Clicked on entries - brings the user directly to the Flatpak's store page within Bazaar.

  • Tested on Niri

  • Tested on Hyprland

  • Tested on Sway

  • Tested on another compositor:

  • Noctalia version tested against: v5.0.0 (712144465c44)

  • Plugin API level: 3

Screenshots / Videos

plugin_trailer.mp4

Checklist

  • The directory name matches the part of id after the / in plugin.toml exactly.
  • It ships plugin.toml, README.md, thumbnail.webp, and translations/en.json.
  • README.md follows the
    README template, documents
    every entry id and dependency, and includes exact panel IPC commands and launcher prefixes where applicable.
  • I created thumbnail.webp with the thumbnail generator.
  • version follows semver and is bumped in this PR; plugin_api is the oldest API level this plugin requires.
  • Every non-English translation in this PR uses a locale supported by Noctalia core, and I can read, write, and
    understand that language well enough to review and maintain it (no unreviewed machine/LLM translations).
  • I did not edit catalog.toml; CI generates it.
  • This PR touches exactly one plugin directory.

Code review attestation

Plugins run as trusted, unsandboxed Luau in the user's session. Confirm:

  • The code is readable and not obfuscated, minified, or generated.
  • It does not download and execute remote code.
  • Every network call, filesystem write, and spawned process is something the description above accounts for.
  • I have the right to publish this code under the license declared in plugin.toml.

@ItsLemmy

Copy link
Copy Markdown
Contributor
  1. blocking - bazaarsearch/launcher.luau:94

The launcher query is interpolated into a shell command using single quotes, but embedded quotes are replaced with '. POSIX single-quoted strings do not treat backslashes as escapes, so a crafted /bzr query can terminate the argument and execute arbitrary shell commands.

Noctalia executes string-form runAsync calls through /bin/sh. A harmless reproduction using the same quoting logic successfully created a marker file. The plugin runs unsandboxed in the user's session, making this arbitrary command execution.

The same unsafe construction affects Bazaar-provided result IDs at bazaarsearch/launcher.luau:137 and bazaarsearch/launcher.luau:170. Every dynamic argument must use correct POSIX shell quoting, or the process API must accept and execute an argument vector without a shell.

  1. non-blocking - bazaarsearch/plugin.toml:12

The declared dependencies list bazaar and busctl, but activation also spawns date through command substitution at bazaarsearch/launcher.luau:170.
bazaarsearch/README.md:18 also claims that only busctl and Bazaar are required.

Declare and document date, or remove the external command dependency by obtaining the timestamp without spawning it.

@ItsLemmy
ItsLemmy marked this pull request as draft July 29, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants