Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Better money spent than on Omarchy.
  • My trust in Flatpak diminished after installing the book reader Calibre and finding that despite the sandboxing Calibre was given blanket access to my drive. Apparently a quirk of the developer behind Calibre insisting upon it. No warnings or communication of the exception were given. All trust I had in Flatpak was eroded from that moment on. Curious about the podman options or similar. Having desktop apps in a container with selective access to system resources seems like it would be more secure and configurable if configured correctly. Flatpak as it stands seems to be a legacy solution to what should be a container and namespacing solution.
  • The Soverign Tech Agency are currently hiring for a Director of Technology. Definitely a dream job for someone. https://www.sovereign.tech/jobs/director-of-technology
  • I avoid flatpaks and snaps as much as I can.

    Here is a little blog post from 2021 that lists some of the huge issues flatpaks have https://ludocode.com/blog/flatpak-is-not-the-future

    If you want to sandbox your programs highly recommend looking at firejail.

  • I loved Flatpak until I started building a MiniPC with a 112 GB internal disk for HTPC usage... Then I felt the pain of having to get all slightly different dependency versions for each little program I wanted.

    The box' cost already topped the project's budget so no new disk for it. I'm back to "proper .deb packaging please"

  • I never understood why a program installed in Flatpak is not just a directory on disk.

    When you install something via Flatpak, it still changes data in god-knows-what places on my disk. And the software itself has read/write access to god-knows-where on my disk.

    The answer is probably "convenience and efficiency". But I would much prefer a "An application is a directory and by default cannot access anything outside of that directory" approach.

  • I’m thankful for the STF. Germany is one of the few countries doing something. But it is not strategic software-development.

        * They don’t employ software-developers. No safety for the developers. No control over developers.
        * It is only temporary.
        * The projects need to apply repeatingly for funding. Wasting time and resources and chausing worries.
    
    
    The how planet needs Linux, BSD, cURL, ffmpeg, Flatpak. We need to ensure that this work for the people.

    We feed for 30 years constantly money into monopolies. We shall feed the next century constantly money into things the people need.

    Many developers of Linux and GCC are paid. Because companies decided it is necessary.

  • It's great that there's more investment being put into Flatpak development. The page mentions adding more granular permissions, which is nice to see. However, another necessary improvement is actually making it possible for software to incorporate these new granular permissions in a backwards compatible manner.

    As one example, I maintain a game on Flathub that supports game controllers as an input device. By default, access to game controllers are blocked in the sandbox just like access to any other piece of hardware. The only way to use game controllers is to mark your software as requiring a blanket permission that grants access to all devices connected to the user's system. The Flatpak maintainers realized this is problematic, so a few years ago they added a permission to specifically request access to input devices (https://github.com/flatpak/flatpak/pull/5481). However, because the permissions aren't backwards compatible, and because there's LTS distros under active support with old Flatpak versions released before the permission was added, you aren't allowed to use this permission on Flathub, only the blanket "all devices" permission. As a result, Flathub lists my game as "potentially unsafe" because it "can access hardware devices such as webcams and game controllers" since the only other option was disabling controller support on the Flatpak version of the game.

    If they figure out a way to implement the new permissions so they can fall back to the broader kind on old Flatpak versions, this would be a massive improvement over the current situation. Otherwise you'll have to wait 10+ years before you can use newly added permissions because the only other option is breaking Flatpak on whatever ancient Ubuntu or RHEL version is still under support.

Explore Birbla archives

Sovereign Tech Agency invests €500k in Flatpak · Birbla