No filesystem access for a flatpak app just means it cant read host system files on its own, without user permission. You can still give it files or directories of files through the file explorer for the app to work with, just that it’s much safer since it can only otherwise view files in its sandbox.
[…] aren’t there some folks who want flatpak/snap/appimage to basically replace traditional package managers?
There might be people who think that, but that isn’t realistic. Flatpak is a package manager for user facing apps, mostly gui apps.
The core system apps will still be installed by a system package manager. I.e rpm-ostree on immutable Fedora or transactional-update/zypper on OpenSUSE MicroOS.
Snap can do system apps and user facing apps and fully snap-based Ubuntu might come in the future.
But this won’t force people to use them. Traditional package managers will keep existing for system apps and maintainers will proabably keep their gui packages in the repos.
There’s Obfuscate, an image redactor, and Metadata Cleaner which is self-descriptive. Both works properly without any filesystem access at all, because they use the file picker portal to ask the user for the files to be processed.
I remember in 1995-ish or something when I used the internet for the first time using the Netscape browser… And I was asking a friend if he had tried all the web sites yet. Just got a weird look back… :) I didn’t know what the internet was back then at first.
What if your app actually needs access to the internet?
Or actually do anything useful? No network, no filesystem… it’s a hello world app isn’t it…
No filesystem access for a flatpak app just means it cant read host system files on its own, without user permission. You can still give it files or directories of files through the file explorer for the app to work with, just that it’s much safer since it can only otherwise view files in its sandbox.
Which is fine for some apps, try that with an IDE.
Why does an IDE need unfettered access to my whole FS? Access to the project directory, and maybe the runtime directory, have to be enough.
To be fair, the title says more apps, not all apps…
deleted by creator
As if sandboxes are some brand new concept…
Of course people want them for some use-cases. No one here is saying that every application in the world should be restricted that way, grandpa.
Maybe not here in this thread, but aren’t there some folks who want flatpak/snap/appimage to basically replace traditional package managers?
Doesn’t make it a prevailing attitude worthy of whatever nonsense that other guy is spouting.
There might be people who think that, but that isn’t realistic. Flatpak is a package manager for user facing apps, mostly gui apps.
The core system apps will still be installed by a system package manager. I.e rpm-ostree on immutable Fedora or transactional-update/zypper on OpenSUSE MicroOS.
Snap can do system apps and user facing apps and fully snap-based Ubuntu might come in the future.
But this won’t force people to use them. Traditional package managers will keep existing for system apps and maintainers will proabably keep their gui packages in the repos.
Yeah things like selinux and apparmor have been around for a long time, sandboxing is just an evolution of that
deleted by creator
Nobody was freaking out about sandboxing.
deleted by creator
Says the person speaking for the whole community.
There are portals: https://docs.flatpak.org/en/latest/desktop-integration.html#portals . they allow secure access to many features. Also any flatpak app still has access to a private app-specific filesystem, just not to the host.
Doesn’t work for all applications but for many sand boxing is possible without a loss of features.
Portal.
There’s Obfuscate, an image redactor, and Metadata Cleaner which is self-descriptive. Both works properly without any filesystem access at all, because they use the file picker portal to ask the user for the files to be processed.
Oh come on, what modern program actually needs to communicate or access the file system?
Exactly all programs should be web based cloud subscription only. We don’t want that filthy code on our rgb nvme drives
Lol, sorry no network access either.
Wouldn’t want the gaping security hole open that is hypnotizing the user via RGB control.
BRB, modulating my RGB to send data…
Download the internet along with it!
I’m self-hosting the entire internet. I hope you guys are enjoying yourselves.
https://github.com/iiab/iiab
That’s super cool. I bookmarked it. Thanks!
Lol
Thanks for having us on your server… when can I get out again though?
I just unplugged you. Give it a minute or two and no more pain.
I remember in 1995-ish or something when I used the internet for the first time using the Netscape browser… And I was asking a friend if he had tried all the web sites yet. Just got a weird look back… :) I didn’t know what the internet was back then at first.
The app can then declare the network permission and it will still be marked as safe.
deleted by creator